96 Total advisories
96 Vulnerabilities
0 Malware

Vulnerabilities

CRITICAL 9.6
PyPI

CVE-2026-40088

PraisonAI Vulnerable to OS Command Injection

CRITICAL 9.6
PyPI

CVE-2026-44336

PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection

CRITICAL 9.8
PyPI

CVE-2026-47391

PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution

CRITICAL 9.8
PyPI

CVE-2026-40288

PraisonAI has critical RCE via `type: job` workflow YAML

CRITICAL 9.3
PyPI

CVE-2026-40154

PraisonAI Vulnerable Untrusted Remote Template Code Execution

CRITICAL 9.0
PyPI

CVE-2026-39305

PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator

CRITICAL 9.1
PyPI

CVE-2026-34952

PraisonAI Has Missing Authentication in WebSocket Gateway

CRITICAL 9.8
PyPI

CVE-2026-41497

PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection

CRITICAL 9.8
PyPI

CVE-2026-34935

PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()

CRITICAL 9.8
PyPI

CVE-2026-34934

PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`

UNKNOWN
PyPI

CVE-2026-40157

PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`

CRITICAL 9.1
PyPI

CVE-2026-34953

PraisonAI Has Authentication Bypass via OAuthManager.validate_token()

CRITICAL 9.1
PyPI

CVE-2026-40289

PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

CRITICAL 9.8
PyPI

CVE-2026-47396

PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset

CRITICAL 9.8
PyPI

CVE-2026-47393

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

UNKNOWN
PyPI

CVE-2026-35615

PraisonAI Has Path Traversal in FileTools

CRITICAL 9.9
PyPI

CVE-2026-47392

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

CRITICAL 9.8
PyPI

CVE-2026-39890

PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading

CRITICAL 9.8
PyPI

CVE-2026-34935

PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()

CRITICAL 9.8
PyPI

CVE-2026-34934

PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`

CRITICAL 9.9
PyPI

CVE-2026-47392

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

CRITICAL 9.3
PyPI

CVE-2026-40154

PraisonAI Vulnerable Untrusted Remote Template Code Execution

UNKNOWN
PyPI

CVE-2026-40157

PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`

CRITICAL 9.6
PyPI

CVE-2026-40088

PraisonAI Vulnerable to OS Command Injection

CRITICAL 9.8
PyPI

CVE-2026-47396

PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset

CRITICAL 9.8
PyPI

CVE-2026-41497

PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection

CRITICAL 9.1
PyPI

CVE-2026-34952

PraisonAI Has Missing Authentication in WebSocket Gateway

CRITICAL 9.0
PyPI

CVE-2026-39305

PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator

CRITICAL 9.8
PyPI

CVE-2026-47393

PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

CRITICAL 9.8
PyPI

CVE-2026-47391

PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution

CRITICAL 9.1
PyPI

CVE-2026-34953

PraisonAI Has Authentication Bypass via OAuthManager.validate_token()

UNKNOWN
PyPI

CVE-2026-35615

PraisonAI Has Path Traversal in FileTools

CRITICAL 9.8
PyPI

CVE-2026-40288

PraisonAI has critical RCE via `type: job` workflow YAML

CRITICAL 9.8
PyPI

CVE-2026-39890

PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading

CRITICAL 9.1
PyPI

CVE-2026-40289

PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

CRITICAL 9.6
PyPI

CVE-2026-44336

PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection

HIGH 8.8
PyPI

GHSA-fwh2-95jw-g4j6

Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

MEDIUM 5.5
PyPI

GHSA-x44p-gg67-52fc

Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

HIGH 7.5
PyPI

GHSA-jxcw-qp4h-6jfq

PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default

HIGH 8.1
PyPI

GHSA-f44v-7qgw-9gh9

PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion

HIGH 7.8
PyPI

GHSA-7qw2-w5rc-37x2

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

HIGH 8.8
PyPI

GHSA-6jcq-6546-qrrw

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

HIGH 8.2
PyPI

GHSA-8ccj-p46r-jwqq

PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication

CRITICAL 9.1
PyPI

GHSA-29w3-p9w9-wc47

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

CRITICAL 9.8
PyPI

GHSA-fq2m-6wqh-x44g

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

HIGH 8.6
PyPI

GHSA-x92v-rpx6-p6cw

PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)

HIGH 7.2
PyPI

GHSA-rjvw-7vvw-549v

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

CRITICAL 9.8
PyPI

GHSA-892r-p3jq-jp24

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

HIGH 7.3
PyPI

GHSA-gcq3-mfvh-3x25

PraisonAI Code agent tools fail open without a workspace boundary

CRITICAL 9.8
PyPI

GHSA-p75f-6fp4-p57w

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

HIGH 8.8
PyPI

GHSA-8579-rgg5-ph2m

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

HIGH 8.6
PyPI

GHSA-fc26-m9pf-v56q

PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing

CRITICAL 9.8
PyPI

GHSA-4869-x4pr-q22x

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

HIGH 8.2
PyPI

GHSA-5qw8-f2g9-ff29

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

HIGH 7.5
PyPI

GHSA-22cj-m4wf-fv2c

PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

HIGH 8.8
PyPI

GHSA-63v4-w882-g4x2

PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

HIGH 7.5
PyPI

GHSA-p4pj-vh7h-6cqh

PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API

HIGH 8.3
PyPI

GHSA-vmf9-xx9w-86wx

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

HIGH 8.8
PyPI

GHSA-w6h2-fr4q-xvxv

PraisonAI: Compute-bridged file tools allow shell command injection

HIGH 7.5
PyPI

GHSA-j7qx-p75m-wp7g

PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

HIGH 8.3
PyPI

GHSA-qvpf-j64c-jmhr

PraisonAI Slack app_mention bypasses configured user/channel authorization

CRITICAL 9.8
PyPI

GHSA-j4hj-7hfh-g2f4

praisonai: recipe serve auth middleware silently disables itself when no secret is set

HIGH 7.8
PyPI

GHSA-v847-hxxw-3pxg

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

UNKNOWN
PyPI

CVE-2026-47397

PraisonAI has an Arbitrary File Write in Python API

MEDIUM 5.5
PyPI

CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

UNKNOWN
PyPI

CVE-2026-47394

PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate

MEDIUM 5.5
PyPI

CVE-2026-47390

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

HIGH 8.1
PyPI

CVE-2026-47398

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

HIGH 8.1
PyPI

CVE-2026-41496

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

HIGH 8.4
PyPI

CVE-2026-44334

PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)

HIGH 7.3
PyPI

CVE-2026-44338

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

HIGH 7.5
PyPI

CVE-2026-44340

PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`

HIGH 8.6
PyPI

CVE-2026-44339

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

MEDIUM 6.3
PyPI

CVE-2026-44337

PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries

HIGH 8.4
PyPI

CVE-2026-40287

PraisonAI Vulnerable to RCE via Automatic tools.py Import

UNKNOWN
PyPI

CVE-2026-40315

PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries

HIGH 8.6
PyPI

CVE-2026-40158

PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure

MEDIUM 6.5
PyPI

CVE-2026-40148

PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits

MEDIUM 5.4
PyPI

CVE-2026-40112

PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)

MEDIUM 6.2
PyPI

CVE-2026-40115

PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS

HIGH 8.8
PyPI

GHSA-qwgj-rrpj-75xm

PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution

HIGH 7.2
PyPI

CVE-2026-40114

PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API

HIGH 7.8
PyPI

CVE-2026-40156

PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading

HIGH 7.5
PyPI

CVE-2026-40116

PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits

MEDIUM 5.5
PyPI

CVE-2026-40159

PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution

HIGH 8.4
PyPI

CVE-2026-40113

PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars

MEDIUM 5.3
PyPI

CVE-2026-40151

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS

HIGH 7.9
PyPI

CVE-2026-40149

PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls

HIGH 8.8
PyPI

CVE-2026-39891

PraisonAI has Template Injection in Agent Tool Definitions

HIGH 7.5
PyPI

CVE-2026-39889

PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server

HIGH 7.1
PyPI

CVE-2026-39308

PraisonAI recipe registry publish path traversal allows out-of-root file write

HIGH 8.1
PyPI

CVE-2026-39307

PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction

HIGH 7.3
PyPI

CVE-2026-39306

PraisonAI recipe registry pull path traversal writes files outside the chosen output directory

HIGH 7.7
PyPI

CVE-2026-34936

PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback

MEDIUM 6.5
PyPI

CVE-2026-34939

PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()

HIGH 8.8
PyPI

CVE-2026-34955

PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox

Ready to move

Start Securing

Free, no credit card | First findings in minutes