Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

mervinpraison — Vulnerabilities & Security Advisories 113

Browse all 113 CVE security advisories affecting mervinpraison. AI-powered Chinese analysis, POCs, and references for each vulnerability.

mervinpraison is primarily associated with open-source automation and scripting tools, often utilized for system administration and data processing tasks. Security audits have identified forty-five Common Vulnerabilities and Exposures (CVEs) linked to this entity, predominantly stemming from legacy codebases and insufficient input validation. The most frequently observed vulnerability classes include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), which arise from improper sanitization of user-supplied data. Additionally, several instances of insecure direct object references and privilege escalation flaws have been documented, reflecting gaps in access control mechanisms. These issues typically affect older versions of the software suite, with patches available for recent releases. The profile indicates a pattern of reactive security maintenance rather than proactive secure development, necessitating careful version management for users relying on these tools in production environments.

CVE ID Title CVSS Severity Published
CVE-2026-44339 PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute — PraisonAI CWE-470 8.6 High 2026-05-08
CVE-2026-44338 PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution — PraisonAI CWE-306 7.3 High 2026-05-08
CVE-2026-44337 PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries — PraisonAI CWE-20 6.3 Medium 2026-05-08
CVE-2026-44336 PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection — PraisonAI CWE-20 5.4AI Medium AI 2026-05-08
CVE-2026-44335 SSRF bypass in PraisonAI — PraisonAI CWE-918 9.1AI Critical AI 2026-05-08
CVE-2026-44334 PraisonAI: Unauthenticated RCE via `tool_override.py` — PraisonAI CWE-94 8.4 High 2026-05-08
CVE-2026-41497 Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI — PraisonAI CWE-78 9.8 Critical 2026-05-08
CVE-2026-41496 PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315) — PraisonAI CWE-89 8.1 High 2026-05-08
CVE-2026-40313 PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence — PraisonAI CWE-829 9.1 Critical 2026-04-14
CVE-2026-40289 PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions — PraisonAI CWE-306 9.1 Critical 2026-04-14
CVE-2026-40288 PraisonAI: Critical RCE via `type: job` workflow YAML — PraisonAI CWE-78 9.8 Critical 2026-04-14
CVE-2026-40287 PraisonAI has RCE via Automatic tools.py Import — PraisonAI CWE-94 8.4 High 2026-04-14
CVE-2026-40315 PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries — PraisonAI CWE-89 8.1 - 2026-04-14
CVE-2026-40160 PraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback — PraisonAIAgents CWE-918 7.4AI High AI 2026-04-10
CVE-2026-40159 PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution — PraisonAI CWE-200 5.5 Medium 2026-04-10
CVE-2026-40158 PraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonai — PraisonAI CWE-94 8.6 High 2026-04-10
CVE-2026-40157 PraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack` — PraisonAI CWE-22 8.1 - 2026-04-10
CVE-2026-40156 PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading — PraisonAI CWE-94 7.8 High 2026-04-10
CVE-2026-40154 PraisonAI Affected by Untrusted Remote Template Code Execution — PraisonAI CWE-829 9.3 Critical 2026-04-09
CVE-2026-40151 PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS — PraisonAI CWE-200 5.3 Medium 2026-04-09
CVE-2026-40153 PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool — PraisonAIAgents CWE-526 7.4 High 2026-04-09
CVE-2026-40152 PraisonAIAgents has a Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary — PraisonAIAgents CWE-22 5.3 Medium 2026-04-09
CVE-2026-40150 PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool — PraisonAIAgents CWE-918 7.7 High 2026-04-09
CVE-2026-40149 PraisonAI has an Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls — PraisonAI CWE-396 7.9 High 2026-04-09
CVE-2026-40148 PraisonAI Affected by Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits — PraisonAI CWE-409 6.5 Medium 2026-04-09
CVE-2026-40117 PraisonAIAgents Affected by Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate — PraisonAIAgents CWE-862 6.2 Medium 2026-04-09
CVE-2026-40116 PraisonAI's Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits — PraisonAI CWE-770 7.5 High 2026-04-09
CVE-2026-40115 PraisonAI has an Unrestricted Upload Size in WSGI Recipe Registry Server Enables Memory Exhaustion DoS — PraisonAI CWE-770 6.2 Medium 2026-04-09
CVE-2026-40114 PraisonAI has Server-Side Request Forgery via Unvalidated webhook_url in Jobs API — PraisonAI CWE-918 7.2 High 2026-04-09
CVE-2026-40113 PraisonAI has an Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars — PraisonAI CWE-88 8.4 High 2026-04-09

This page lists every published CVE security advisory associated with mervinpraison. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.