PraisonAI 是一个多智能体团队系统。在 praisonai 4.6.58 版本之前,Browser Server 的 方法使用 检查 Chrome 扩展的源,匹配的正则表达式为未锚定的 。由于该正则表达式未限制尾部字符,攻击者可以在匹配的 32 位字符后附加额外字符,从而绕过验证,在调用 之前发起 命令,导致未经授权的浏览器自动化操作。此问题已在版本 4.6.58 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.58 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55541 | 8.8 HIGH | PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced |
| CVE-2026-55534 | 8.6 HIGH | PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent executi |
| CVE-2026-55539 | 8.6 HIGH | PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — |
| CVE-2026-55526 | 8.5 HIGH | PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved ho |
| CVE-2026-55528 | 8.2 HIGH | praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-8 |
| CVE-2026-55533 | 8.2 HIGH | PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when AP |
| CVE-2026-55532 | 7.6 HIGH | PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cros |
| CVE-2026-55525 | 7.5 HIGH | PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl |
| CVE-2026-55538 | 7.3 HIGH | PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-in |
| CVE-2026-55537 | 7.1 HIGH | PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — b |
| CVE-2026-55527 | 7.1 HIGH | PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — pat |
| CVE-2026-55540 | 7.1 HIGH | PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks |
| CVE-2026-55529 | 6.9 MEDIUM | PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated u |
| CVE-2026-55535 | 6.8 MEDIUM | PraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation |
| CVE-2026-55531 | 6.5 MEDIUM | PraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server |
| CVE-2026-55530 | 6.1 MEDIUM | PraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate en |
No comments yet