Vulnerabilities
CVE-2026-40088
PraisonAI Vulnerable to OS Command Injection
CVE-2026-44336
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
CVE-2026-47391
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
CVE-2026-40288
PraisonAI has critical RCE via `type: job` workflow YAML
CVE-2026-40154
PraisonAI Vulnerable Untrusted Remote Template Code Execution
CVE-2026-39305
PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator
CVE-2026-34952
PraisonAI Has Missing Authentication in WebSocket Gateway
CVE-2026-41497
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
CVE-2026-34935
PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()
CVE-2026-34934
PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`
CVE-2026-40157
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
CVE-2026-34953
PraisonAI Has Authentication Bypass via OAuthManager.validate_token()
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
CVE-2026-47396
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
CVE-2026-47393
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-35615
PraisonAI Has Path Traversal in FileTools
CVE-2026-47392
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CVE-2026-39890
PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
CVE-2026-34935
PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()
CVE-2026-34934
PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`
CVE-2026-47392
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CVE-2026-40154
PraisonAI Vulnerable Untrusted Remote Template Code Execution
CVE-2026-40157
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
CVE-2026-40088
PraisonAI Vulnerable to OS Command Injection
CVE-2026-47396
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
CVE-2026-41497
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
CVE-2026-34952
PraisonAI Has Missing Authentication in WebSocket Gateway
CVE-2026-39305
PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator
CVE-2026-47393
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-47391
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
CVE-2026-34953
PraisonAI Has Authentication Bypass via OAuthManager.validate_token()
CVE-2026-35615
PraisonAI Has Path Traversal in FileTools
CVE-2026-40288
PraisonAI has critical RCE via `type: job` workflow YAML
CVE-2026-39890
PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
CVE-2026-44336
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
GHSA-fwh2-95jw-g4j6
Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-x44p-gg67-52fc
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
GHSA-jxcw-qp4h-6jfq
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
GHSA-f44v-7qgw-9gh9
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
GHSA-7qw2-w5rc-37x2
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
GHSA-6jcq-6546-qrrw
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
GHSA-8ccj-p46r-jwqq
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
GHSA-29w3-p9w9-wc47
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
GHSA-fq2m-6wqh-x44g
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
GHSA-x92v-rpx6-p6cw
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
GHSA-rjvw-7vvw-549v
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
GHSA-892r-p3jq-jp24
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
GHSA-gcq3-mfvh-3x25
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-p75f-6fp4-p57w
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
GHSA-8579-rgg5-ph2m
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
GHSA-fc26-m9pf-v56q
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
GHSA-4869-x4pr-q22x
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
GHSA-5qw8-f2g9-ff29
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
GHSA-22cj-m4wf-fv2c
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-63v4-w882-g4x2
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
GHSA-p4pj-vh7h-6cqh
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
GHSA-vmf9-xx9w-86wx
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
GHSA-w6h2-fr4q-xvxv
PraisonAI: Compute-bridged file tools allow shell command injection
GHSA-j7qx-p75m-wp7g
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
GHSA-qvpf-j64c-jmhr
PraisonAI Slack app_mention bypasses configured user/channel authorization
GHSA-j4hj-7hfh-g2f4
praisonai: recipe serve auth middleware silently disables itself when no secret is set
GHSA-v847-hxxw-3pxg
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
CVE-2026-47397
PraisonAI has an Arbitrary File Write in Python API
CVE-2026-47395
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47394
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-47390
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-47398
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-41496
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CVE-2026-44334
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
CVE-2026-44338
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-44340
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-44337
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
CVE-2026-40287
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-40315
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
CVE-2026-40158
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
CVE-2026-40148
PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
CVE-2026-40112
PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
CVE-2026-40115
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
GHSA-qwgj-rrpj-75xm
PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution
CVE-2026-40114
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
CVE-2026-40156
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVE-2026-40116
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVE-2026-40159
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
CVE-2026-40113
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
CVE-2026-40151
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
CVE-2026-40149
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
CVE-2026-39891
PraisonAI has Template Injection in Agent Tool Definitions
CVE-2026-39889
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
CVE-2026-39308
PraisonAI recipe registry publish path traversal allows out-of-root file write
CVE-2026-39307
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
CVE-2026-39306
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
CVE-2026-34936
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
CVE-2026-34939
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
CVE-2026-34955
PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
Ready to move
Start Securing
Free, no credit card | First findings in minutes