Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

mervinpraison — Vulnerabilities & Security Advisories 113

Browse all 113 CVE security advisories affecting mervinpraison. AI-powered Chinese analysis, POCs, and references for each vulnerability.

mervinpraison is primarily associated with open-source automation and scripting tools, often utilized for system administration and data processing tasks. Security audits have identified forty-five Common Vulnerabilities and Exposures (CVEs) linked to this entity, predominantly stemming from legacy codebases and insufficient input validation. The most frequently observed vulnerability classes include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), which arise from improper sanitization of user-supplied data. Additionally, several instances of insecure direct object references and privilege escalation flaws have been documented, reflecting gaps in access control mechanisms. These issues typically affect older versions of the software suite, with patches available for recent releases. The profile indicates a pattern of reactive security maintenance rather than proactive secure development, necessitating careful version management for users relying on these tools in production environments.

CVE ID Title CVSS Severity Published
CVE-2026-61446 PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery — PraisonAI CWE-94 8.4 High 2026-07-15
CVE-2026-61443 PraisonAI before 1.6.78 Remote Code Execution via SkillTools — PraisonAI CWE-22 8.1 High 2026-07-15
CVE-2026-61440 PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints — PraisonAI CWE-862 6.5 Medium 2026-07-15
CVE-2026-61438 PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox — PraisonAI CWE-78 7.3 High 2026-07-15
CVE-2026-61435 PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing — PraisonAI CWE-287 8.2 High 2026-07-15
CVE-2026-61436 PraisonAI before 4.6.78 Missing Webhook Signature Verification — PraisonAI CWE-287 8.6 High 2026-07-15
CVE-2026-61433 PraisonAI before 4.6.78 Code Injection via API deployment generator — PraisonAI CWE-94 7.8 High 2026-07-15
CVE-2026-61427 PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream — PraisonAI CWE-20 7.3 High 2026-07-15
CVE-2026-61430 PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl — PraisonAI CWE-918 8.5 High 2026-07-15
CVE-2026-60087 PraisonAI before 1.6.78 Tool Approval Cache Bypass — PraisonAI CWE-863 6.1 Medium 2026-07-15
CVE-2026-60085 PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox — PraisonAI CWE-273 7.5 High 2026-07-15
CVE-2026-61447 PraisonAI before 1.6.78 Remote Code Execution via CodeAgent — PraisonAI CWE-94 10.0 Critical 2026-07-11
CVE-2026-61442 PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH — PraisonAI CWE-862 7.1 High 2026-07-11
CVE-2026-61445 PraisonAI before 4.6.78 Arbitrary File Write and Command Execution — PraisonAI CWE-22 9.9 Critical 2026-07-11
CVE-2026-61439 PraisonAI before 4.6.78 Prompt Injection Defense Bypass — PraisonAI CWE-1188 7.5 High 2026-07-11
CVE-2026-61429 PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend — PraisonAI CWE-918 8.5 High 2026-07-11
CVE-2026-61428 PraisonAI AgentMail before 4.6.78 Message Injection via Webhook — PraisonAI CWE-290 7.3 High 2026-07-11
CVE-2026-61426 PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults — PraisonAI CWE-200 8.6 High 2026-07-11
CVE-2026-60088 PraisonAI before 4.6.78 Path Traversal via Custom Commands — PraisonAI CWE-22 5.5 Medium 2026-07-11
CVE-2026-60090 PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension — PraisonAI CWE-89 9.8 Critical 2026-07-11
CVE-2026-61444 PraisonAI before 4.6.78 Code Injection via f-string — PraisonAI CWE-94 9.1 Critical 2026-07-10
CVE-2026-61441 PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies — PraisonAI CWE-862 6.5 Medium 2026-07-10
CVE-2026-61437 PraisonAI before 1.6.78 Remote Code Execution via tools.py — PraisonAI CWE-693 7.8 High 2026-07-10
CVE-2026-61434 PraisonAI before 4.6.78 Allowlist Bypass via find -exec — PraisonAI CWE-78 8.8 High 2026-07-10
CVE-2026-61432 PraisonAI FastContext before 1.6.78 Path Traversal — PraisonAI CWE-22 5.7 Medium 2026-07-10
CVE-2026-60091 PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url — PraisonAI CWE-918 7.2 High 2026-07-10
CVE-2026-61431 PraisonAI before 4.6.78 Path Traversal via ContextGatherer — PraisonAI CWE-22 5.5 Medium 2026-07-10
CVE-2026-60089 PraisonAI before 1.6.78 Path Traversal via config.toml — PraisonAI CWE-22 5.5 Medium 2026-07-10
CVE-2026-60086 PraisonAI before 4.6.78 Prompt Injection Defense Bypass — PraisonAI CWE-693 5.3 Medium 2026-07-10
CVE-2026-44340 PraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir` — PraisonAI CWE-22 7.1AI High AI 2026-05-08

This page lists every published CVE security advisory associated with mervinpraison. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.