39 Total advisories
39 Vulnerabilities
0 Malware
Vulnerabilities
CRITICAL 9.8
CVE-2026-40288
PraisonAI has critical RCE via `type: job` workflow YAML
UNKNOWN
CVE-2026-40111
PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
CRITICAL 9.9
CVE-2026-39888
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
CRITICAL 9.1
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
CRITICAL 10.0
CVE-2026-34938
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
CRITICAL 9.9
CVE-2026-47392
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CRITICAL 10.0
CVE-2026-34938
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
CRITICAL 9.9
CVE-2026-47392
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CRITICAL 9.9
CVE-2026-39888
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
UNKNOWN
CVE-2026-40111
PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
CRITICAL 9.8
CVE-2026-40288
PraisonAI has critical RCE via `type: job` workflow YAML
CRITICAL 9.1
CVE-2026-40289
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
MEDIUM 5.5
CVE-2026-56074
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
MEDIUM 6.5
CVE-2026-56078
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
HIGH 8.1
GHSA-c969-5x3p-vq3v
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
HIGH 8.8
GHSA-4pcv-mg8v-vrgf
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
HIGH 7.5
GHSA-2rcg-mm5h-xchx
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
CRITICAL 9.8
GHSA-x8cv-xmq7-p8xp
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
MEDIUM 6.5
GHSA-6h9p-93hq-q7h6
PraisonAI: SpiderTools redirect-target SSRF protection bypass
CRITICAL 9.8
GHSA-4869-x4pr-q22x
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
MEDIUM 4.3
GHSA-35w5-pcw4-jx94
PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
CRITICAL 9.8
GHSA-x227-pf99-vffg
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
HIGH 8.3
GHSA-vmf9-xx9w-86wx
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
HIGH 8.5
GHSA-vxgj-xg5c-p4h7
praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
MEDIUM 6.5
GHSA-pv2j-rghr-v5r9
PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
MEDIUM 5.5
CVE-2026-47395
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
MEDIUM 5.5
CVE-2026-47390
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
HIGH 8.1
CVE-2026-41496
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
CRITICAL 9.8
CVE-2026-44335
PraisonAI has an SSRF bypass
HIGH 8.6
CVE-2026-44339
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
HIGH 8.4
CVE-2026-40287
PraisonAI Vulnerable to RCE via Automatic tools.py Import
HIGH 7.7
CVE-2026-40150
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
HIGH 7.4
CVE-2026-40153
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
UNKNOWN
CVE-2026-40160
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
MEDIUM 5.3
CVE-2026-40152
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
MEDIUM 6.2
CVE-2026-40117
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
HIGH 8.1
GHSA-x462-jjpc-q4q4
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
HIGH 7.8
CVE-2026-34937
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution
HIGH 8.6
CVE-2026-34954
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL
Ready to move
Start Securing
Free, no credit card | First findings in minutes