Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PraisonAI — Vulnerabilities & Security Advisories 94

All 94 CVE vulnerabilities found in PraisonAI, with AI-generated Chinese analysis, references, and POCs.

This page details known vulnerabilities associated with PraisonAI, a large language model framework. It serves as a centralized resource for tracking security weaknesses and advisory notifications linked to this specific technology stack. The content focuses on common vulnerability classes such as input validation flaws, improper authentication mechanisms, and potential injection attacks that may arise from the integration of LLM components within software architectures. The collection encompasses reported security issues identified over the past year, providing a chronological overview of discovered defects and their respective remediation statuses. This timeframe allows users to assess the evolution of security practices and the frequency of patch releases for PraisonAI. By aggregating these data points, the page aims to offer a comprehensive view of the product's risk landscape without overwhelming the reader with fragmented information. Visitors can utilize this resource to monitor vendor advisories and stay informed about emerging threats specific to PraisonAI implementations. It also facilitates a deeper understanding of particular weakness categories, helping developers and security analysts recognize patterns in how these flaws manifest. Furthermore, users can look up the historical record of vulnerabilities for PraisonAI to evaluate the stability and security maturity of the product over time. This structured approach supports informed decision-making regarding system integration and ongoing maintenance protocols.

Vendor: MervinPraison

CVE IDTitleCVSSSeverityPublished
CVE-2026-55524 PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) CWE-367 7.5 High2026-08-05
CVE-2026-55523 PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets CWE-918 7.7 High2026-08-05
CVE-2026-55522 PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code CWE-94 7.8 High2026-08-05
CVE-2026-48168 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name CWE-862 10.0 Critical2026-08-05
CVE-2026-47398 PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334 CWE-94 8.1 High2026-07-21
CVE-2026-47397 PraisonAI has an Arbitrary File Write in Python API CWE-22 7.1 High2026-07-21
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset CWE-284 9.8 Critical2026-07-21
CVE-2026-47395 PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context CWE-200 5.5 Medium2026-07-21
CVE-2026-47394 PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate CWE-22--2026-07-21
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default CWE-306 9.8 Critical2026-07-21
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) CWE-184 9.9 Critical2026-07-21
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution CWE-95 9.8 Critical2026-07-21
CVE-2026-47390 PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings CWE-918 5.5 Medium2026-07-21
CVE-2026-61446 PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery CWE-94 8.4 High2026-07-15
CVE-2026-61443 PraisonAI before 1.6.78 Remote Code Execution via SkillTools CWE-22 8.1 High2026-07-15
CVE-2026-61440 PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints CWE-862 6.5 Medium2026-07-15
CVE-2026-61438 PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox CWE-78 7.3 High2026-07-15
CVE-2026-61436 PraisonAI before 4.6.78 Missing Webhook Signature Verification CWE-287 8.6 High2026-07-15
CVE-2026-61435 PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing CWE-287 8.2 High2026-07-15
CVE-2026-61433 PraisonAI before 4.6.78 Code Injection via API deployment generator CWE-94 7.8 High2026-07-15
CVE-2026-61430 PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl CWE-918 8.5 High2026-07-15
CVE-2026-61427 PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream CWE-20 7.3 High2026-07-15
CVE-2026-60087 PraisonAI before 1.6.78 Tool Approval Cache Bypass CWE-863 6.1 Medium2026-07-15
CVE-2026-60085 PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox CWE-273 7.5 High2026-07-15
CVE-2026-61447 PraisonAI before 1.6.78 Remote Code Execution via CodeAgent CWE-94 10.0 Critical2026-07-11
CVE-2026-61445 PraisonAI before 4.6.78 Arbitrary File Write and Command Execution CWE-22 9.9 Critical2026-07-11
CVE-2026-61442 PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH CWE-862 7.1 High2026-07-11
CVE-2026-61439 PraisonAI before 4.6.78 Prompt Injection Defense Bypass CWE-1188 7.5 High2026-07-11
CVE-2026-61428 PraisonAI AgentMail before 4.6.78 Message Injection via Webhook CWE-290 7.3 High2026-07-11
CVE-2026-61429 PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend CWE-918 8.5 High2026-07-11

All 94 known CVE vulnerabilities affecting PraisonAI with full Chinese analysis, references, and POCs where available.