以下是该漏洞描述的中文翻译: PraisonAI 是一个多智能体团队系统。从 1.2.3 到 1.7.2 版本中, 中的 网络隔离模式存在缺陷:其 函数仅通过注入无效的 和 环境变量来实现所谓的“网络隔离”,并未在操作系统层面建立真正的网络边界。 这意味着,那些忽略这些代理变量的程序可以直接打开套接字(socket),使得本应被隔离的命令能够访问本地主机(localhost)、内部服务、云元数据接口或外部主机,从而可能导致数据泄露。 该问题的初步修复措施已在版本 1.7.2 中发布。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | >= 1.2.3, < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57138 | 9.9 CRITICAL | PraisonAI codeMode sandbox escape via Function constructor |
| CVE-2026-57139 | 9.8 CRITICAL | PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
| CVE-2026-57141 | 9.8 CRITICAL | PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool |
| CVE-2026-57147 | 9.8 CRITICAL | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forger |
| CVE-2026-57148 | 9.8 CRITICAL | praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (def |
| CVE-2026-57140 | 9.4 CRITICAL | PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
| CVE-2026-57133 | 8.8 HIGH | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
| CVE-2026-57136 | 8.8 HIGH | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
| CVE-2026-57137 | 8.8 HIGH | PraisonAI AgentLoop onToolCall approval runs after tool execution |
| CVE-2026-57112 | 8.3 HIGH | PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes reg |
| CVE-2026-57134 | 8.2 HIGH | PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials witho |
No comments yet