Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PraisonAI — Vulnerabilities & Security Advisories 135

All 135 CVE vulnerabilities found in PraisonAI, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the PraisonAI product, focusing on specific weakness types and associated tags relevant to the vendor. It collects security advisories and historical vulnerability records, covering the full range of disclosed issues within the monitored timeframe. Readers can track PraisonAI advisories, analyze the evolution of a specific weakness class, and review the product's complete vulnerability history to identify recurring patterns or long-standing exposure risks.

Vendor: MervinPraison

CVE ID Title CVSS Severity Published
CVE-2026-55535 PraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation CWE-367 6.8 Medium 2026-08-25
CVE-2026-55537 PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114 CWE-367 7.1 High 2026-08-25
CVE-2026-55538 PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated CWE-306 7.3 High 2026-08-25
CVE-2026-55540 PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks CWE-22 7.1 High 2026-08-25
CVE-2026-55530 PraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool CWE-862 6.1 Medium 2026-08-25
CVE-2026-55534 PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution CWE-306 8.6 High 2026-08-25
CVE-2026-55526 PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`) CWE-350 8.5 High 2026-08-25
CVE-2026-55531 PraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced) CWE-400 6.5 Medium 2026-08-25
CVE-2026-55528 praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862) CWE-306 8.2 High 2026-08-25
CVE-2026-55529 PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP server CWE-306 6.9 Medium 2026-08-25
CVE-2026-55525 PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl CWE-918 7.5 High 2026-08-25
CVE-2026-55524 PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) CWE-367 7.5 High 2026-08-05
CVE-2026-55523 PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets CWE-918 7.7 High 2026-08-05
CVE-2026-55522 PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code CWE-94 7.8 High 2026-08-05
CVE-2026-48168 PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name CWE-862 10.0 Critical 2026-08-05
CVE-2026-47398 PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334 CWE-94 8.1 High 2026-07-21
CVE-2026-47397 PraisonAI has an Arbitrary File Write in Python API CWE-22 7.1 High 2026-07-21
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset CWE-284 9.8 Critical 2026-07-21
CVE-2026-47395 PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context CWE-200 5.5 Medium 2026-07-21
CVE-2026-47394 PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate CWE-22 - - 2026-07-21
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default CWE-306 9.8 Critical 2026-07-21
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) CWE-184 9.9 Critical 2026-07-21
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution CWE-95 9.8 Critical 2026-07-21
CVE-2026-47390 PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings CWE-918 5.5 Medium 2026-07-21
CVE-2026-61446 PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery CWE-94 8.4 High 2026-07-15
CVE-2026-61440 PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints CWE-862 6.5 Medium 2026-07-15
CVE-2026-61443 PraisonAI before 1.6.78 Remote Code Execution via SkillTools CWE-22 8.1 High 2026-07-15
CVE-2026-61438 PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox CWE-78 7.3 High 2026-07-15
CVE-2026-61435 PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing CWE-287 8.2 High 2026-07-15
CVE-2026-61436 PraisonAI before 4.6.78 Missing Webhook Signature Verification CWE-287 8.6 High 2026-07-15

All 135 known CVE vulnerabilities affecting PraisonAI with full Chinese analysis, references, and POCs where available.