Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PraisonAI — Vulnerabilities & Security Advisories 90

All 90 CVE vulnerabilities found in PraisonAI, with AI-generated Chinese analysis, references, and POCs.

This page details known vulnerabilities associated with PraisonAI, a large language model framework. It serves as a centralized resource for tracking security weaknesses and advisory notifications linked to this specific technology stack. The content focuses on common vulnerability classes such as input validation flaws, improper authentication mechanisms, and potential injection attacks that may arise from the integration of LLM components within software architectures. The collection encompasses reported security issues identified over the past year, providing a chronological overview of discovered defects and their respective remediation statuses. This timeframe allows users to assess the evolution of security practices and the frequency of patch releases for PraisonAI. By aggregating these data points, the page aims to offer a comprehensive view of the product's risk landscape without overwhelming the reader with fragmented information. Visitors can utilize this resource to monitor vendor advisories and stay informed about emerging threats specific to PraisonAI implementations. It also facilitates a deeper understanding of particular weakness categories, helping developers and security analysts recognize patterns in how these flaws manifest. Furthermore, users can look up the historical record of vulnerabilities for PraisonAI to evaluate the stability and security maturity of the product over time. This structured approach supports informed decision-making regarding system integration and ongoing maintenance protocols.

Vendor: MervinPraison

CVE IDTitleCVSSSeverityPublished
CVE-2026-61441 PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies CWE-862 6.5 Medium2026-07-10
CVE-2026-61434 PraisonAI before 4.6.78 Allowlist Bypass via find -exec CWE-78 8.8 High2026-07-10
CVE-2026-61437 PraisonAI before 1.6.78 Remote Code Execution via tools.py CWE-693 7.8 High2026-07-10
CVE-2026-61432 PraisonAI FastContext before 1.6.78 Path Traversal CWE-22 5.7 Medium2026-07-10
CVE-2026-60091 PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url CWE-918 7.2 High2026-07-10
CVE-2026-61431 PraisonAI before 4.6.78 Path Traversal via ContextGatherer CWE-22 5.5 Medium2026-07-10
CVE-2026-60089 PraisonAI before 1.6.78 Path Traversal via config.toml CWE-22 5.5 Medium2026-07-10
CVE-2026-60086 PraisonAI before 4.6.78 Prompt Injection Defense Bypass CWE-693 5.3 Medium2026-07-10
CVE-2026-58653 PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update CWE-639 4.3 Medium2026-07-02
CVE-2026-56078 PraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor CWE-22 8.8 High2026-06-18
CVE-2026-56077 PraisonAI - Information Disclosure via Shared MultiAgentLedger State CWE-668 6.5 Medium2026-06-18
CVE-2026-56076 PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint CWE-942 8.1 High2026-06-18
CVE-2026-56074 PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching CWE-863 5.5 Medium2026-06-18
CVE-2026-56075 PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override CWE-863 8.8 High2026-06-18
CVE-2026-44340 PraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir` CWE-22 7.1AIHighAI2026-05-08
CVE-2026-44339 PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute CWE-470 8.6 High2026-05-08
CVE-2026-44338 PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution CWE-306 7.3 High2026-05-08
CVE-2026-44337 PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries CWE-20 6.3 Medium2026-05-08
CVE-2026-44336 PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection CWE-20 5.4AIMediumAI2026-05-08
CVE-2026-44335 SSRF bypass in PraisonAI CWE-918 9.1AICriticalAI2026-05-08
CVE-2026-44334 PraisonAI: Unauthenticated RCE via `tool_override.py` CWE-94 8.4 High2026-05-08
CVE-2026-41497 Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI CWE-78 9.8 Critical2026-05-08
CVE-2026-41496 PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315) CWE-89 8.1 High2026-05-08
CVE-2026-40313 PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence CWE-829 9.1 Critical2026-04-14
CVE-2026-40289 PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions CWE-306 9.1 Critical2026-04-14
CVE-2026-40288 PraisonAI: Critical RCE via `type: job` workflow YAML CWE-78 9.8 Critical2026-04-14
CVE-2026-40287 PraisonAI has RCE via Automatic tools.py Import CWE-94 8.4 High2026-04-14
CVE-2026-40315 PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries CWE-89 8.1 -2026-04-14
CVE-2026-40159 PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution CWE-200 5.5 Medium2026-04-10
CVE-2026-40158 PraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonai CWE-94 8.6 High2026-04-10

All 90 known CVE vulnerabilities affecting PraisonAI with full Chinese analysis, references, and POCs where available.