Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 4.6.78之前版本存在路径遍历漏洞,该漏洞源于ContextGatherer组件未能验证.praisoncontext和.praisoninclude文件中的包含路径,攻击者可提供绝对路径或父目录遍历序列,导致读取工作区之外的文件并包含其内容在生成的上下文中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MervinPraison | PraisonAI | < 4.6.78 |
affected |
4.6.78 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | 0 ~ 4.6.78 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61444 | 9.1 CRITICAL | PraisonAI before 4.6.78 Code Injection via f-string |
| CVE-2026-61434 | 8.8 HIGH | PraisonAI before 4.6.78 Allowlist Bypass via find -exec |
| CVE-2026-61437 | 7.8 HIGH | PraisonAI before 1.6.78 Remote Code Execution via tools.py |
| CVE-2026-60091 | 7.2 HIGH | PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url |
| CVE-2026-61441 | 6.5 MEDIUM | PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies |
| CVE-2026-61432 | 5.7 MEDIUM | PraisonAI FastContext before 1.6.78 Path Traversal |
| CVE-2026-60089 | 5.5 MEDIUM | PraisonAI before 1.6.78 Path Traversal via config.toml |
| CVE-2026-60086 | 5.3 MEDIUM | PraisonAI before 4.6.78 Prompt Injection Defense Bypass |
No comments yet