PraisonAI 是一个多智能体(multi-agent)团队协作系统。在 1.4.0 至 1.7.2 版本中, 中的 功能使用 在名为 的包装环境中执行不受信任的 JavaScript 代码,并依赖于一个较小的源码黑名单以及被遮蔽(shadowed)的 和 属性来实现沙箱隔离。 然而,攻击者控制的 输入代码可以通过 恢复真正的 构造函数,进而获取未被遮蔽的 对象及 ,从而绕过标榜的沙箱机制,访问宿主机的文件系统和子进程 API。攻击者能够读取敏感信息、修改文件、执行命令,甚至导致宿主进程资源耗尽。 该问题已在
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | >= 1.4.0, < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57139 | 9.8 CRITICAL | PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
| CVE-2026-57141 | 9.8 CRITICAL | PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool |
| CVE-2026-57147 | 9.8 CRITICAL | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forger |
| CVE-2026-57148 | 9.8 CRITICAL | praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (def |
| CVE-2026-57140 | 9.4 CRITICAL | PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
| CVE-2026-57133 | 8.8 HIGH | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
| CVE-2026-57136 | 8.8 HIGH | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
| CVE-2026-57137 | 8.8 HIGH | PraisonAI AgentLoop onToolCall approval runs after tool execution |
| CVE-2026-57112 | 8.3 HIGH | PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes reg |
| CVE-2026-57134 | 8.2 HIGH | PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials witho |
| CVE-2026-57135 | 7.6 HIGH | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network cli |
No comments yet