Dependency scanning
Check whether praisonaiagents is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-56074
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-55522
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
CVE-2026-55522
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
CVE-2026-55524
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
CVE-2026-55526
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
CVE-2026-55530
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
CVE-2026-55525
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
CVE-2026-55528
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
CVE-2026-55527
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
CVE-2026-55523
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
CVE-2026-55526
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
CVE-2026-55524
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
CVE-2026-55528
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
CVE-2026-55530
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
CVE-2026-55527
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
CVE-2026-55523
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
CVE-2026-55525
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
GHSA-x462-jjpc-q4q4
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
CVE-2026-56074
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
CVE-2026-57125
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
CVE-2026-57125
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
CVE-2026-57118
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
CVE-2026-57143
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
CVE-2026-57129
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
CVE-2026-57128
PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
CVE-2026-57126
praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
CVE-2026-57123
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
CVE-2026-57130
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
CVE-2026-57112
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
CVE-2026-57112
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
CVE-2026-57120
PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
CVE-2026-57115
PraisonAI: SpiderTools redirect-target SSRF protection bypass
CVE-2026-57123
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
CVE-2026-57118
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
CVE-2026-57126
praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
CVE-2026-57120
PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
CVE-2026-57130
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
CVE-2026-57115
PraisonAI: SpiderTools redirect-target SSRF protection bypass
CVE-2026-57129
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
CVE-2026-57143
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
CVE-2026-57128
PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
CVE-2026-40160
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
CVE-2026-47395
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47395
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-40287
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-40287
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-47390
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-47390
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-40153
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-34937
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
CVE-2026-40117
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
CVE-2026-40152
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
CVE-2026-56078
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
CVE-2026-40150
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
CVE-2026-34954
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
CVE-2026-41496
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CVE-2026-41496
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CVE-2026-44335
PraisonAI has an SSRF bypass
CVE-2026-44335
PraisonAI has an SSRF bypass
CVE-2026-40152
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
CVE-2026-40117
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
CVE-2026-40150
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
CVE-2026-56078
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
CVE-2026-34954
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
CVE-2026-40153
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
CVE-2026-34937
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
CVE-2026-40160
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
CVE-2026-39888
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
CVE-2026-34938
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
CVE-2026-40288
PraisonAI has critical RCE via `type: job` workflow YAML
CVE-2026-40111
PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
CVE-2026-47392
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CVE-2026-34938
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
CVE-2026-47392
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CVE-2026-39888
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
CVE-2026-40111
PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
CVE-2026-40288
PraisonAI has critical RCE via `type: job` workflow YAML
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes