Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 1.6.78之前版本存在路径遍历漏洞,该漏洞源于FastContext功能存在路径遍历,FastContextAgent.execute_tool()仅在相对路径前添加工作区路径,未拒绝绝对路径或规范化连接路径,导致工具参数或模型生成的函数调用可通过绝对路径或'../'遍历序列读取、搜索和枚举工作区目录外的文件,并将文件内容返回给调用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MervinPraison | PraisonAI | < 1.6.78 |
affected |
1.6.78 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | 0 ~ 1.6.78 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61444 | 9.1 CRITICAL | PraisonAI before 4.6.78 Code Injection via f-string |
| CVE-2026-61434 | 8.8 HIGH | PraisonAI before 4.6.78 Allowlist Bypass via find -exec |
| CVE-2026-61437 | 7.8 HIGH | PraisonAI before 1.6.78 Remote Code Execution via tools.py |
| CVE-2026-60091 | 7.2 HIGH | PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url |
| CVE-2026-61441 | 6.5 MEDIUM | PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies |
| CVE-2026-60089 | 5.5 MEDIUM | PraisonAI before 1.6.78 Path Traversal via config.toml |
| CVE-2026-61431 | 5.5 MEDIUM | PraisonAI before 4.6.78 Path Traversal via ContextGatherer |
| CVE-2026-60086 | 5.3 MEDIUM | PraisonAI before 4.6.78 Prompt Injection Defense Bypass |
No comments yet