PraisonAI 是一个多智能体团队系统。在 0.1.6 版本之前, 在 未设置时,会回退到公开的 HS256 签名密钥;同时,由于 也默认为 ,启动检查和令牌签发守卫均处于禁用状态。未认证的攻击者可以签发包含攻击者自选 值的 JWT,而 会将其接受为已认证身份,从而在已知目标标识符时实现用户或工作区所有者的身份冒充。该漏洞已在 praisonai-platform 0.1.6 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.51 | - |
|
| MervinPraison | praisonai-platform | < 0.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57138 | 9.9 CRITICAL | PraisonAI codeMode sandbox escape via Function constructor |
| CVE-2026-57139 | 9.8 CRITICAL | PraisonAI MCPServer exposes unauthenticated HTTP tools/call |
| CVE-2026-57141 | 9.8 CRITICAL | PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool |
| CVE-2026-57147 | 9.8 CRITICAL | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forger |
| CVE-2026-57140 | 9.4 CRITICAL | PraisonAI AgentOS exposes unauthenticated agent listing and invocation |
| CVE-2026-57133 | 8.8 HIGH | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
| CVE-2026-57136 | 8.8 HIGH | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
| CVE-2026-57137 | 8.8 HIGH | PraisonAI AgentLoop onToolCall approval runs after tool execution |
| CVE-2026-57112 | 8.3 HIGH | PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes reg |
| CVE-2026-57134 | 8.2 HIGH | PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials witho |
| CVE-2026-57135 | 7.6 HIGH | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network cli |
No comments yet