PraisonAI 是一个多智能体(multi-agent)团队系统。在 1.7.2 版本之前,位于 中的 工具使用 配合 来执行模型生成的 JavaScript 代码。然而,其基于正则表达式的黑名单机制可以被绕过:攻击者可通过 获取全局对象,并通过动态构造 模块名来突破限制。 若攻击者能够影响传入 工具的 参数,则可以利用宿主机进程的能力,读写文件、获取环境变量中的凭证,并以 PraisonAI 进程的权限执行操作系统命令。该问题已在版本 1.7.2 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 1.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57138 | 9.9 CRITICAL | PraisonAI codeMode sandbox escape via Function constructor |
| CVE-2026-57139 | 9.8 CRITICAL | PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
| CVE-2026-57147 | 9.8 CRITICAL | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forger |
| CVE-2026-57148 | 9.8 CRITICAL | praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (def |
| CVE-2026-57140 | 9.4 CRITICAL | PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
| CVE-2026-57133 | 8.8 HIGH | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
| CVE-2026-57136 | 8.8 HIGH | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
| CVE-2026-57137 | 8.8 HIGH | PraisonAI AgentLoop onToolCall approval runs after tool execution |
| CVE-2026-57112 | 8.3 HIGH | PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes reg |
| CVE-2026-57134 | 8.2 HIGH | PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials witho |
| CVE-2026-57135 | 7.6 HIGH | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network cli |
No comments yet