Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 4.6.40之前版本存在安全漏洞,该漏洞源于praisonai/agents_generator.py中缺失了对spec.loader.exec_module调用站点的验证,允许从YAML配置获取的module_path参数未经验证、签名检查或环境变量门控直接执行,可能导致代码注入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.40 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.40 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: spec.loader.exec_module ran attacker module_path; exfiltrated PROOF_624ed5312164f0db from /flag.txt via AgentsGenerator.load_tools_from_module[_class]
| CVE-2026-47392 | 9.9 CRITICAL | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execu |
| CVE-2026-47393 | 9.8 CRITICAL | PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
| CVE-2026-47396 | 9.8 CRITICAL | PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when |
| CVE-2026-47391 | 9.8 CRITICAL | PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool e |
| CVE-2026-47410 | 9.8 CRITICAL | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing |
| CVE-2026-47413 | 9.6 CRITICAL | praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspa |
| CVE-2026-47416 | 9.6 CRITICAL | praisonai-platform: Any workspace member can promote themselves (or any other member) to o |
| CVE-2026-47405 | 8.8 HIGH | PraisonAI Platform missing role checks let any workspace member become owner and take over |
| CVE-2026-47399 | 8.8 HIGH | PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global o |
| CVE-2026-47415 | 8.3 HIGH | praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, |
| CVE-2026-47419 | 8.3 HIGH | praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, |
| CVE-2026-47409 | 8.1 HIGH | praisonai-platform: Any workspace member can remove any other member (including the owner) |
| CVE-2026-47417 | 8.1 HIGH | praisonai-platform: Comment endpoints accept any issue_id without workspace ownership chec |
| CVE-2026-47412 | 8.1 HIGH | praisonai-platform: Any workspace member can delete the entire workspace via DELETE /works |
| CVE-2026-47418 | 8.1 HIGH | praisonai-platform: Project endpoints accept any project_id without workspace ownership ch |
| CVE-2026-47406 | 8.1 HIGH | praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace |
| CVE-2026-47414 | 7.6 HIGH | praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace |
| CVE-2026-47397 | 7.1 HIGH | PraisonAI has an Arbitrary File Write in Python API |
| CVE-2026-47408 | 6.5 MEDIUM | praisonai-platform: list_issue_activity returns activity log for any issue regardless of w |
| CVE-2026-47411 | 6.5 MEDIUM | praisonai-platform: Any workspace member can rewrite workspace name, description, and sett |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet