Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PraisonAI — Vulnerabilities & Security Advisories 135

All 135 CVE vulnerabilities found in PraisonAI, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the PraisonAI product, focusing on specific weakness types and associated tags relevant to the vendor. It collects security advisories and historical vulnerability records, covering the full range of disclosed issues within the monitored timeframe. Readers can track PraisonAI advisories, analyze the evolution of a specific weakness class, and review the product's complete vulnerability history to identify recurring patterns or long-standing exposure risks.

Vendor: MervinPraison

CVE ID Title CVSS Severity Published
CVE-2026-57147 praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery CWE-798 9.8 Critical 2026-09-15
CVE-2026-57148 praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) CWE-287 9.8 Critical 2026-09-15
CVE-2026-57140 PraisonAI AgentOS exposes unauthenticated agent listing and invocation CWE-306 9.4 Critical 2026-09-15
CVE-2026-57139 PraisonAI MCPServer exposes unauthenticated HTTP tools/call CWE-306 9.8 Critical 2026-09-15
CVE-2026-57133 PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining CWE-78 8.8 High 2026-09-15
CVE-2026-57135 PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients CWE-653 7.6 High 2026-09-15
CVE-2026-57134 PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation CWE-287 8.2 High 2026-09-15
CVE-2026-57138 PraisonAI codeMode sandbox escape via Function constructor CWE-184 9.9 Critical 2026-09-15
CVE-2026-57136 PraisonAI SandboxExecutor allowedCommands bypass via shell chaining CWE-78 8.8 High 2026-09-15
CVE-2026-57137 PraisonAI AgentLoop onToolCall approval runs after tool execution CWE-693 8.8 High 2026-09-15
CVE-2026-57141 PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool CWE-94 9.8 Critical 2026-09-15
CVE-2026-57112 PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools CWE-306 8.3 High 2026-09-15
CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation CWE-22 9.1 Critical 2026-09-14
CVE-2026-57132 PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication CWE-287 8.2 High 2026-09-14
CVE-2026-57131 praisonai: Jobs API exposes agent-execution endpoints with no authentication CWE-94 9.8 Critical 2026-09-14
CVE-2026-57124 PraisonAI UI MCP connect endpoint allows unauthenticated local command execution CWE-78 9.8 Critical 2026-09-14
CVE-2026-57122 PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots) CWE-345 8.6 High 2026-09-14
CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set CWE-306 9.8 Critical 2026-09-14
CVE-2026-56839 PraisonAI Code agent tools fail open without a workspace boundary CWE-22 7.3 High 2026-09-14
CVE-2026-57119 PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API CWE-22 7.5 High 2026-09-14
CVE-2026-57126 praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS CWE-918 8.5 High 2026-09-14
CVE-2026-57128 PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint CWE-306 4.3 Medium 2026-09-14
CVE-2026-57115 PraisonAI: SpiderTools redirect-target SSRF protection bypass CWE-918 6.5 Medium 2026-09-14
CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass CWE-306 9.8 Critical 2026-09-14
CVE-2026-55536 Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) CWE-284 9.1 Critical 2026-08-25
CVE-2026-55532 PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server CWE-346 7.6 High 2026-08-25
CVE-2026-55533 PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret CWE-287 8.2 High 2026-08-25
CVE-2026-55539 PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete CWE-306 8.6 High 2026-08-25
CVE-2026-55527 PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location CWE-22 7.1 High 2026-08-25
CVE-2026-55541 PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced CWE-862 8.8 High 2026-08-25

All 135 known CVE vulnerabilities affecting PraisonAI with full Chinese analysis, references, and POCs where available.