Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

praisonaiagents — Vulnerabilities & Security Advisories 11

All 11 CVE vulnerabilities found in praisonaiagents, with AI-generated Chinese analysis, references, and POCs.

Vendor: MervinPraison

CVE ID Title CVSS Severity Published
CVE-2026-57129 PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal CWE-22 7.5 High 2026-09-14
CVE-2026-57120 PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder CWE-693 6.5 Medium 2026-09-14
CVE-2026-57123 PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in CWE-306 9.8 Critical 2026-09-14
CVE-2026-57130 PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters CWE-20 8.1 High 2026-09-14
CVE-2026-40160 PraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback CWE-918 7.4AI High AI 2026-04-10
CVE-2026-40153 PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool CWE-526 7.4 High 2026-04-09
CVE-2026-40152 PraisonAIAgents has a Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary CWE-22 5.3 Medium 2026-04-09
CVE-2026-40150 PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool CWE-918 7.7 High 2026-04-09
CVE-2026-40117 PraisonAIAgents Affected by Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate CWE-862 6.2 Medium 2026-04-09
CVE-2026-40111 PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py) CWE-78 7.8AI High AI 2026-04-09
CVE-2026-39888 PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode) CWE-657 10.0 Critical 2026-04-08

All 11 known CVE vulnerabilities affecting praisonaiagents with full Chinese analysis, references, and POCs where available.