Dependency scanning
Check whether praisonai is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-55533
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
CVE-2026-55522
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
CVE-2026-55522
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
CVE-2026-55535
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
CVE-2026-55534
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
CVE-2026-55537
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
CVE-2026-55529
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
CVE-2026-55536
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
CVE-2026-55540
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
CVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
CVE-2026-55538
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
CVE-2026-55531
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
CVE-2026-55539
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
CVE-2026-55541
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
CVE-2026-55539
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
CVE-2026-55540
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
CVE-2026-55534
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
CVE-2026-55529
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
CVE-2026-55536
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
CVE-2026-55538
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
CVE-2026-55533
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
CVE-2026-55531
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
CVE-2026-55537
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
CVE-2026-55541
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
CVE-2026-55535
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
CVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
GHSA-x44p-gg67-52fc
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-57113
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
CVE-2026-57125
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
CVE-2026-57125
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
CVE-2026-56840
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
CVE-2026-56832
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
CVE-2026-57132
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
CVE-2026-57145
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
CVE-2026-56833
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
CVE-2026-56837
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
CVE-2026-57119
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
CVE-2026-56834
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
CVE-2026-57146
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
CVE-2026-57144
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
CVE-2026-56839
PraisonAI Code agent tools fail open without a workspace boundary
CVE-2026-57131
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
CVE-2026-57122
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
CVE-2026-56838
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
CVE-2026-57112
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
CVE-2026-57112
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
CVE-2026-56836
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
CVE-2026-56835
PraisonAI Slack app_mention bypasses configured user/channel authorization
CVE-2026-57116
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
CVE-2026-57114
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
CVE-2026-57142
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
CVE-2026-57117
PraisonAI: Compute-bridged file tools allow shell command injection
CVE-2026-57127
praisonai: recipe serve auth middleware silently disables itself when no secret is set
CVE-2026-57124
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
CVE-2026-57122
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
CVE-2026-57117
PraisonAI: Compute-bridged file tools allow shell command injection
CVE-2026-57124
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
CVE-2026-57119
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
CVE-2026-56838
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
CVE-2026-57146
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
CVE-2026-57114
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
CVE-2026-56835
PraisonAI Slack app_mention bypasses configured user/channel authorization
CVE-2026-57113
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
CVE-2026-56837
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
CVE-2026-57116
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
CVE-2026-57142
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
CVE-2026-57132
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
CVE-2026-57145
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
CVE-2026-57127
praisonai: recipe serve auth middleware silently disables itself when no secret is set
CVE-2026-56839
PraisonAI Code agent tools fail open without a workspace boundary
CVE-2026-56834
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
CVE-2026-57131
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
CVE-2026-56832
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
CVE-2026-57144
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
CVE-2026-56840
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
CVE-2026-56836
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
CVE-2026-56833
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
CVE-2026-47393
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-44338
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVE-2026-47398
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-47398
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-40148
PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
CVE-2026-34955
PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
CVE-2026-40116
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
CVE-2026-39308
PraisonAI recipe registry publish path traversal allows out-of-root file write
CVE-2026-47395
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47395
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-34939
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
CVE-2026-40287
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-40287
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-47390
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-47390
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-34936
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-39889
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
CVE-2026-40115
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
CVE-2026-40112
PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
CVE-2026-39891
PraisonAI has Template Injection in Agent Tool Definitions
CVE-2026-40159
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes