100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether praisonai is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.2
PyPI

CVE-2026-55533

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

HIGH 7.8
PyPI

CVE-2026-55522

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

HIGH 7.8
PyPI

CVE-2026-55522

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

MEDIUM 6.8
PyPI

CVE-2026-55535

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

HIGH 8.6
PyPI

CVE-2026-55534

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

HIGH 7.1
PyPI

CVE-2026-55537

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

MEDIUM 6.9
PyPI

CVE-2026-55529

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

CRITICAL 9.1
PyPI

CVE-2026-55536

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

HIGH 7.1
PyPI

CVE-2026-55540

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

HIGH 7.6
PyPI

CVE-2026-55532

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

HIGH 7.3
PyPI

CVE-2026-55538

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

MEDIUM 6.5
PyPI

CVE-2026-55531

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

HIGH 8.6
PyPI

CVE-2026-55539

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

UNKNOWN
PyPI

CVE-2026-55541

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

HIGH 8.6
PyPI

CVE-2026-55539

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

HIGH 7.1
PyPI

CVE-2026-55540

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

HIGH 8.6
PyPI

CVE-2026-55534

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

MEDIUM 6.9
PyPI

CVE-2026-55529

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

CRITICAL 9.1
PyPI

CVE-2026-55536

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

HIGH 7.3
PyPI

CVE-2026-55538

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

HIGH 8.2
PyPI

CVE-2026-55533

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

MEDIUM 6.5
PyPI

CVE-2026-55531

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

HIGH 7.1
PyPI

CVE-2026-55537

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

UNKNOWN
PyPI

CVE-2026-55541

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

MEDIUM 6.8
PyPI

CVE-2026-55535

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

HIGH 7.6
PyPI

CVE-2026-55532

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

MEDIUM 5.5
PyPI

GHSA-x44p-gg67-52fc

Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

HIGH 8.1
PyPI

CVE-2026-57113

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

CRITICAL 9.8
PyPI

CVE-2026-57125

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

CRITICAL 9.8
PyPI

CVE-2026-57125

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

HIGH 8.8
PyPI

CVE-2026-56840

PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

HIGH 8.8
PyPI

CVE-2026-56832

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

HIGH 8.2
PyPI

CVE-2026-57132

PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication

CRITICAL 9.1
PyPI

CVE-2026-57145

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

HIGH 7.5
PyPI

CVE-2026-56833

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

HIGH 8.6
PyPI

CVE-2026-56837

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

HIGH 7.5
PyPI

CVE-2026-57119

PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API

HIGH 7.5
PyPI

CVE-2026-56834

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

HIGH 7.5
PyPI

CVE-2026-57146

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

HIGH 8.8
PyPI

CVE-2026-57144

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

HIGH 7.3
PyPI

CVE-2026-56839

PraisonAI Code agent tools fail open without a workspace boundary

CRITICAL 9.8
PyPI

CVE-2026-57131

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

HIGH 8.6
PyPI

CVE-2026-57122

PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)

HIGH 7.8
PyPI

CVE-2026-56838

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

HIGH 8.3
PyPI

CVE-2026-57112

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

HIGH 8.3
PyPI

CVE-2026-57112

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

HIGH 8.2
PyPI

CVE-2026-56836

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

HIGH 8.3
PyPI

CVE-2026-56835

PraisonAI Slack app_mention bypasses configured user/channel authorization

CRITICAL 9.8
PyPI

CVE-2026-57116

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

HIGH 7.2
PyPI

CVE-2026-57114

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

HIGH 7.8
PyPI

CVE-2026-57142

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

HIGH 8.8
PyPI

CVE-2026-57117

PraisonAI: Compute-bridged file tools allow shell command injection

CRITICAL 9.8
PyPI

CVE-2026-57127

praisonai: recipe serve auth middleware silently disables itself when no secret is set

CRITICAL 9.8
PyPI

CVE-2026-57124

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

HIGH 8.6
PyPI

CVE-2026-57122

PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)

HIGH 8.8
PyPI

CVE-2026-57117

PraisonAI: Compute-bridged file tools allow shell command injection

CRITICAL 9.8
PyPI

CVE-2026-57124

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

HIGH 7.5
PyPI

CVE-2026-57119

PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API

HIGH 7.8
PyPI

CVE-2026-56838

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

HIGH 7.5
PyPI

CVE-2026-57146

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

HIGH 7.2
PyPI

CVE-2026-57114

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

HIGH 8.3
PyPI

CVE-2026-56835

PraisonAI Slack app_mention bypasses configured user/channel authorization

HIGH 8.1
PyPI

CVE-2026-57113

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

HIGH 8.6
PyPI

CVE-2026-56837

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

CRITICAL 9.8
PyPI

CVE-2026-57116

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

HIGH 7.8
PyPI

CVE-2026-57142

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

HIGH 8.2
PyPI

CVE-2026-57132

PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication

CRITICAL 9.1
PyPI

CVE-2026-57145

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

CRITICAL 9.8
PyPI

CVE-2026-57127

praisonai: recipe serve auth middleware silently disables itself when no secret is set

HIGH 7.3
PyPI

CVE-2026-56839

PraisonAI Code agent tools fail open without a workspace boundary

HIGH 7.5
PyPI

CVE-2026-56834

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

CRITICAL 9.8
PyPI

CVE-2026-57131

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

HIGH 8.8
PyPI

CVE-2026-56832

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

HIGH 8.8
PyPI

CVE-2026-57144

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

HIGH 8.8
PyPI

CVE-2026-56840

PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

HIGH 8.2
PyPI

CVE-2026-56836

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

HIGH 7.5
PyPI

CVE-2026-56833

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

CRITICAL 9.8
PyPI

CVE-2026-47393

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

HIGH 7.3
PyPI

CVE-2026-44338

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

HIGH 8.1
PyPI

CVE-2026-47398

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

HIGH 8.1
PyPI

CVE-2026-47398

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

MEDIUM 6.5
PyPI

CVE-2026-40148

PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits

HIGH 8.8
PyPI

CVE-2026-34955

PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox

HIGH 7.5
PyPI

CVE-2026-40116

PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits

HIGH 7.1
PyPI

CVE-2026-39308

PraisonAI recipe registry publish path traversal allows out-of-root file write

MEDIUM 5.5
PyPI

CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

MEDIUM 5.5
PyPI

CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

MEDIUM 6.5
PyPI

CVE-2026-34939

PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()

HIGH 8.4
PyPI

CVE-2026-40287

PraisonAI Vulnerable to RCE via Automatic tools.py Import

HIGH 8.4
PyPI

CVE-2026-40287

PraisonAI Vulnerable to RCE via Automatic tools.py Import

MEDIUM 5.5
PyPI

CVE-2026-47390

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

MEDIUM 5.5
PyPI

CVE-2026-47390

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

HIGH 7.7
PyPI

CVE-2026-34936

PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback

HIGH 8.6
PyPI

CVE-2026-44339

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

HIGH 8.6
PyPI

CVE-2026-44339

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

HIGH 7.5
PyPI

CVE-2026-39889

PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server

MEDIUM 6.2
PyPI

CVE-2026-40115

PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS

MEDIUM 5.4
PyPI

CVE-2026-40112

PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)

HIGH 8.8
PyPI

CVE-2026-39891

PraisonAI has Template Injection in Agent Tool Definitions

MEDIUM 5.5
PyPI

CVE-2026-40159

PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes