PraisonAI PraisonAI是PraisonAI公司的一款整合人工智能代理的服务器中间件软件。 PraisonAI 1.5.128之前版本存在配置错误漏洞,该漏洞源于AGUI端点存在跨源代理执行漏洞,/agui端点缺少身份验证并硬编码Access-Control-Allow-Origin: *标头,结合Starlette的JSON解析方式,允许攻击者绕过CORS预检检查并窃取敏感代理响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56078 | 8.8 HIGH | PraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor |
| CVE-2026-56075 | 8.8 HIGH | PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override |
| CVE-2026-56077 | 6.5 MEDIUM | PraisonAI - Information Disclosure via Shared MultiAgentLedger State |
| CVE-2026-56074 | 5.5 MEDIUM | PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching |
No comments yet