Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

mervinpraison — Vulnerabilities & Security Advisories 113

Browse all 113 CVE security advisories affecting mervinpraison. AI-powered Chinese analysis, POCs, and references for each vulnerability.

mervinpraison is primarily associated with open-source automation and scripting tools, often utilized for system administration and data processing tasks. Security audits have identified forty-five Common Vulnerabilities and Exposures (CVEs) linked to this entity, predominantly stemming from legacy codebases and insufficient input validation. The most frequently observed vulnerability classes include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), which arise from improper sanitization of user-supplied data. Additionally, several instances of insecure direct object references and privilege escalation flaws have been documented, reflecting gaps in access control mechanisms. These issues typically affect older versions of the software suite, with patches available for recent releases. The profile indicates a pattern of reactive security maintenance rather than proactive secure development, necessitating careful version management for users relying on these tools in production environments.

Found 88 results / 113 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-61426 PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults — PraisonAI CWE-200 8.6 High 2026-07-11
CVE-2026-60090 PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension — PraisonAI CWE-89 9.8 Critical 2026-07-11
CVE-2026-60088 PraisonAI before 4.6.78 Path Traversal via Custom Commands — PraisonAI CWE-22 5.5 Medium 2026-07-11
CVE-2026-61444 PraisonAI before 4.6.78 Code Injection via f-string — PraisonAI CWE-94 9.1 Critical 2026-07-10
CVE-2026-61441 PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies — PraisonAI CWE-862 6.5 Medium 2026-07-10
CVE-2026-61434 PraisonAI before 4.6.78 Allowlist Bypass via find -exec — PraisonAI CWE-78 8.8 High 2026-07-10
CVE-2026-61437 PraisonAI before 1.6.78 Remote Code Execution via tools.py — PraisonAI CWE-693 7.8 High 2026-07-10
CVE-2026-61432 PraisonAI FastContext before 1.6.78 Path Traversal — PraisonAI CWE-22 5.7 Medium 2026-07-10
CVE-2026-60091 PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url — PraisonAI CWE-918 7.2 High 2026-07-10
CVE-2026-61431 PraisonAI before 4.6.78 Path Traversal via ContextGatherer — PraisonAI CWE-22 5.5 Medium 2026-07-10
CVE-2026-60089 PraisonAI before 1.6.78 Path Traversal via config.toml — PraisonAI CWE-22 5.5 Medium 2026-07-10
CVE-2026-60086 PraisonAI before 4.6.78 Prompt Injection Defense Bypass — PraisonAI CWE-693 5.3 Medium 2026-07-10
CVE-2026-44340 PraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir` — PraisonAI CWE-22 7.1AI High AI 2026-05-08
CVE-2026-44339 PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute — PraisonAI CWE-470 8.6 High 2026-05-08
CVE-2026-44338 PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution — PraisonAI CWE-306 7.3 High 2026-05-08
CVE-2026-44337 PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries — PraisonAI CWE-20 6.3 Medium 2026-05-08
CVE-2026-44336 PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection — PraisonAI CWE-20 5.4AI Medium AI 2026-05-08
CVE-2026-44335 SSRF bypass in PraisonAI — PraisonAI CWE-918 9.1AI Critical AI 2026-05-08
CVE-2026-44334 PraisonAI: Unauthenticated RCE via `tool_override.py` — PraisonAI CWE-94 8.4 High 2026-05-08
CVE-2026-41497 Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI — PraisonAI CWE-78 9.8 Critical 2026-05-08
CVE-2026-41496 PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315) — PraisonAI CWE-89 8.1 High 2026-05-08
CVE-2026-40313 PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence — PraisonAI CWE-829 9.1 Critical 2026-04-14
CVE-2026-40289 PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions — PraisonAI CWE-306 9.1 Critical 2026-04-14
CVE-2026-40288 PraisonAI: Critical RCE via `type: job` workflow YAML — PraisonAI CWE-78 9.8 Critical 2026-04-14
CVE-2026-40287 PraisonAI has RCE via Automatic tools.py Import — PraisonAI CWE-94 8.4 High 2026-04-14
CVE-2026-40315 PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries — PraisonAI CWE-89 8.1 - 2026-04-14
CVE-2026-40159 PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution — PraisonAI CWE-200 5.5 Medium 2026-04-10
CVE-2026-40158 PraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonai — PraisonAI CWE-94 8.6 High 2026-04-10
CVE-2026-40157 PraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack` — PraisonAI CWE-22 8.1 - 2026-04-10
CVE-2026-40156 PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading — PraisonAI CWE-94 7.8 High 2026-04-10

This page lists every published CVE security advisory associated with mervinpraison. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.