pypi

praisonaiagents

View on pypi registry
81 Total advisories
81 Vulnerabilities
0 Malware

Dependency scanning

Check whether praisonaiagents is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.5
PyPI

CVE-2026-56074

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

HIGH 7.8
PyPI

CVE-2026-55522

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

HIGH 7.8
PyPI

CVE-2026-55522

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

HIGH 7.5
PyPI

CVE-2026-55524

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

HIGH 8.5
PyPI

CVE-2026-55526

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

MEDIUM 6.1
PyPI

CVE-2026-55530

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

HIGH 7.5
PyPI

CVE-2026-55525

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

HIGH 8.2
PyPI

CVE-2026-55528

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

HIGH 7.1
PyPI

CVE-2026-55527

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

UNKNOWN
PyPI

CVE-2026-55523

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

HIGH 8.5
PyPI

CVE-2026-55526

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

HIGH 7.5
PyPI

CVE-2026-55524

praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

HIGH 8.2
PyPI

CVE-2026-55528

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

MEDIUM 6.1
PyPI

CVE-2026-55530

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

HIGH 7.1
PyPI

CVE-2026-55527

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

UNKNOWN
PyPI

CVE-2026-55523

praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

HIGH 7.5
PyPI

CVE-2026-55525

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

HIGH 8.1
PyPI

GHSA-x462-jjpc-q4q4

PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

MEDIUM 5.5
PyPI

CVE-2026-56074

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

CRITICAL 9.8
PyPI

CVE-2026-57125

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

CRITICAL 9.8
PyPI

CVE-2026-57125

PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

CRITICAL 9.8
PyPI

CVE-2026-57118

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

HIGH 8.8
PyPI

CVE-2026-57143

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

HIGH 7.5
PyPI

CVE-2026-57129

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

MEDIUM 4.3
PyPI

CVE-2026-57128

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

HIGH 8.5
PyPI

CVE-2026-57126

praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS

CRITICAL 9.8
PyPI

CVE-2026-57123

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

HIGH 8.1
PyPI

CVE-2026-57130

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

HIGH 8.3
PyPI

CVE-2026-57112

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

HIGH 8.3
PyPI

CVE-2026-57112

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

MEDIUM 6.5
PyPI

CVE-2026-57120

PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder

MEDIUM 6.5
PyPI

CVE-2026-57115

PraisonAI: SpiderTools redirect-target SSRF protection bypass

CRITICAL 9.8
PyPI

CVE-2026-57123

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

CRITICAL 9.8
PyPI

CVE-2026-57118

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

HIGH 8.5
PyPI

CVE-2026-57126

praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS

MEDIUM 6.5
PyPI

CVE-2026-57120

PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder

HIGH 8.1
PyPI

CVE-2026-57130

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

MEDIUM 6.5
PyPI

CVE-2026-57115

PraisonAI: SpiderTools redirect-target SSRF protection bypass

HIGH 7.5
PyPI

CVE-2026-57129

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

HIGH 8.8
PyPI

CVE-2026-57143

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

MEDIUM 4.3
PyPI

CVE-2026-57128

PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint

UNKNOWN
PyPI

CVE-2026-40160

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

MEDIUM 5.5
PyPI

CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

MEDIUM 5.5
PyPI

CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context

HIGH 8.4
PyPI

CVE-2026-40287

PraisonAI Vulnerable to RCE via Automatic tools.py Import

HIGH 8.4
PyPI

CVE-2026-40287

PraisonAI Vulnerable to RCE via Automatic tools.py Import

MEDIUM 5.5
PyPI

CVE-2026-47390

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

MEDIUM 5.5
PyPI

CVE-2026-47390

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

HIGH 7.4
PyPI

CVE-2026-40153

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool

HIGH 8.6
PyPI

CVE-2026-44339

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

HIGH 8.6
PyPI

CVE-2026-44339

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

HIGH 7.8
PyPI

CVE-2026-34937

PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution

MEDIUM 6.2
PyPI

CVE-2026-40117

PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate

MEDIUM 5.3
PyPI

CVE-2026-40152

PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary

MEDIUM 6.5
PyPI

CVE-2026-56078

PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

HIGH 7.7
PyPI

CVE-2026-40150

PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool

HIGH 8.6
PyPI

CVE-2026-34954

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

HIGH 8.1
PyPI

CVE-2026-41496

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

HIGH 8.1
PyPI

CVE-2026-41496

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

CRITICAL 9.8
PyPI

CVE-2026-44335

PraisonAI has an SSRF bypass

CRITICAL 9.8
PyPI

CVE-2026-44335

PraisonAI has an SSRF bypass

MEDIUM 5.3
PyPI

CVE-2026-40152

PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary

MEDIUM 6.2
PyPI

CVE-2026-40117

PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate

HIGH 7.7
PyPI

CVE-2026-40150

PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool

MEDIUM 6.5
PyPI

CVE-2026-56078

PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling

HIGH 8.6
PyPI

CVE-2026-34954

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

HIGH 7.4
PyPI

CVE-2026-40153

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool

HIGH 7.8
PyPI

CVE-2026-34937

PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution

UNKNOWN
PyPI

CVE-2026-40160

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

CRITICAL 9.9
PyPI

CVE-2026-39888

PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)

CRITICAL 9.1
PyPI

CVE-2026-40289

PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

CRITICAL 10.0
PyPI

CVE-2026-34938

PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code

CRITICAL 9.8
PyPI

CVE-2026-40288

PraisonAI has critical RCE via `type: job` workflow YAML

UNKNOWN
PyPI

CVE-2026-40111

PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)

CRITICAL 9.9
PyPI

CVE-2026-47392

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

CRITICAL 10.0
PyPI

CVE-2026-34938

PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code

CRITICAL 9.9
PyPI

CVE-2026-47392

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

CRITICAL 9.9
PyPI

CVE-2026-39888

PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)

UNKNOWN
PyPI

CVE-2026-40111

PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)

CRITICAL 9.8
PyPI

CVE-2026-40288

PraisonAI has critical RCE via `type: job` workflow YAML

CRITICAL 9.1
PyPI

CVE-2026-40289

PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes