以下是该漏洞描述的中文翻译: PraisonAI 是一个多智能体团队系统。在 0.1.6 版本之前, 在 未设置时,会将公开的默认值 分配给 。同时,当 也未设置时,其生产环境守卫逻辑不会触发,因为该配置项的默认值是 。 远程未认证的攻击者可以利用这一点,生成带有任意 (主体)和 的 HS256 JWT 令牌。由于平台 方法和 依赖项会接受这种伪造的身份信息,因此受保护的 API 路由存在安全风险。 该漏洞已在 praisonai-platform 0.1.6 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.51 | - |
|
| MervinPraison | praisonai-platform | < 0.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57138 | 9.9 CRITICAL | PraisonAI codeMode sandbox escape via Function constructor |
| CVE-2026-57139 | 9.8 CRITICAL | PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
| CVE-2026-57141 | 9.8 CRITICAL | PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool |
| CVE-2026-57148 | 9.8 CRITICAL | praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (def |
| CVE-2026-57140 | 9.4 CRITICAL | PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
| CVE-2026-57133 | 8.8 HIGH | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
| CVE-2026-57136 | 8.8 HIGH | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
| CVE-2026-57137 | 8.8 HIGH | PraisonAI AgentLoop onToolCall approval runs after tool execution |
| CVE-2026-57112 | 8.3 HIGH | PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes reg |
| CVE-2026-57134 | 8.2 HIGH | PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials witho |
| CVE-2026-57135 | 7.6 HIGH | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network cli |
No comments yet