MervinPraison PraisonAI是MervinPraison个人开发者的 MervinPraison PraisonAI 0.1.4之前版本存在安全漏洞,该漏洞源于工作区授权检查存在缺陷,低权限工作区成员可利用共享依赖项 未严格限制管理员或所有者角色,将自身权限升级为所有者,导致垂直权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MervinPraison | praisonai-platform | < 0.1.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | praisonai-platform | < 0.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: low-privilege member self-escalated to owner (role member->owner, PATCH HTTP 200 with member-only token) PROOF_bf5ea0175c618a1d
| CVE-2026-47392 | 9.9 CRITICAL | PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execu |
| CVE-2026-47393 | 9.8 CRITICAL | PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
| CVE-2026-47396 | 9.8 CRITICAL | PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when |
| CVE-2026-47391 | 9.8 CRITICAL | PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool e |
| CVE-2026-47410 | 9.8 CRITICAL | praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing |
| CVE-2026-47413 | 9.6 CRITICAL | praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspa |
| CVE-2026-47416 | 9.6 CRITICAL | praisonai-platform: Any workspace member can promote themselves (or any other member) to o |
| CVE-2026-47399 | 8.8 HIGH | PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global o |
| CVE-2026-47415 | 8.3 HIGH | praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, |
| CVE-2026-47419 | 8.3 HIGH | praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, |
| CVE-2026-47409 | 8.1 HIGH | praisonai-platform: Any workspace member can remove any other member (including the owner) |
| CVE-2026-47417 | 8.1 HIGH | praisonai-platform: Comment endpoints accept any issue_id without workspace ownership chec |
| CVE-2026-47412 | 8.1 HIGH | praisonai-platform: Any workspace member can delete the entire workspace via DELETE /works |
| CVE-2026-47418 | 8.1 HIGH | praisonai-platform: Project endpoints accept any project_id without workspace ownership ch |
| CVE-2026-47406 | 8.1 HIGH | praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace |
| CVE-2026-47398 | 8.1 HIGH | PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_gen |
| CVE-2026-47414 | 7.6 HIGH | praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace |
| CVE-2026-47397 | 7.1 HIGH | PraisonAI has an Arbitrary File Write in Python API |
| CVE-2026-47408 | 6.5 MEDIUM | praisonai-platform: list_issue_activity returns activity log for any issue regardless of w |
| CVE-2026-47411 | 6.5 MEDIUM | praisonai-platform: Any workspace member can rewrite workspace name, description, and sett |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet