PraisonAI 是一个多智能体协作系统。在 1.4.0 至 1.7.2 版本中, 中的 在调用 审批回调之前,就将可执行工具传递给了 。由于封装的 AI SDK 在生成过程中会执行工具处理器,当该回调返回 (表示拒绝)时,系统仅在已产生副作用且已填充 的已拒绝工具执行之后,才记录 。因此,使用 作为人工或策略审批边界的应用程序,可能会执行已被拒绝的文件、命令、API 调用或数据修改操作。该问题已在 1.7.2 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | >= 1.4.0, < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57138 | 9.9 CRITICAL | PraisonAI codeMode sandbox escape via Function constructor |
| CVE-2026-57139 | 9.8 CRITICAL | PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
| CVE-2026-57141 | 9.8 CRITICAL | PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool |
| CVE-2026-57147 | 9.8 CRITICAL | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forger |
| CVE-2026-57148 | 9.8 CRITICAL | praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (def |
| CVE-2026-57140 | 9.4 CRITICAL | PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
| CVE-2026-57133 | 8.8 HIGH | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
| CVE-2026-57136 | 8.8 HIGH | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
| CVE-2026-57112 | 8.3 HIGH | PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes reg |
| CVE-2026-57134 | 8.2 HIGH | PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials witho |
| CVE-2026-57135 | 7.6 HIGH | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network cli |
No comments yet