CVE-2026-57145PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 09/14/2026 Severity Critical CVE-2026-57132PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication Exploitation status Not confirmed Fix YesAffected product P PraisonAI Published 09/14/2026 Severity High CVE-2026-57131praisonai: Jobs API exposes agent-execution endpoints with no authentication Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 09/14/2026 Severity Critical CVE-2026-57124PraisonAI UI MCP connect endpoint allows unauthenticated local command execution Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 09/14/2026 Severity Critical CVE-2026-57122PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots) Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 09/14/2026 Severity High CVE-2026-57127praisonai: recipe serve auth middleware silently disables itself when no secret is set Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 09/14/2026 Severity Critical CVE-2026-56839PraisonAI Code agent tools fail open without a workspace boundary Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 09/14/2026 Severity High CVE-2026-57119PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API Exploitation status Not confirmed Fix YesAffected product P PraisonAI Published 09/14/2026 Severity High CVE-2026-57129PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal Exploitation status Public exploit Fix YesAffected product P praisonaiagents Published 09/14/2026 Severity High CVE-2026-57126praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 09/14/2026 Severity High CVE-2026-57120PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder Exploitation status Not confirmed Fix YesAffected product P praisonaiagents Published 09/14/2026 Severity Medium CVE-2026-57123PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in Exploitation status Not known exploited Fix YesAffected product P praisonaiagents Published 09/14/2026 Severity Critical CVE-2026-57130PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters Exploitation status Public exploit Fix YesAffected product P praisonaiagents Published 09/14/2026 Severity High CVE-2026-57128PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 09/14/2026 Severity Medium CVE-2026-57115PraisonAI: SpiderTools redirect-target SSRF protection bypass Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 09/14/2026 Severity Medium CVE-2026-57125PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 09/14/2026 Severity Critical CVE-2026-55536Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity Critical CVE-2026-55532PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55533PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55539PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55527PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55541PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55535PraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity Medium CVE-2026-55537PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114 Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55538PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55540PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55530PraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity Medium CVE-2026-55534PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55526PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`) Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55531PraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced) Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity Medium CVE-2026-55528praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862) Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-55529PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP server Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity Medium CVE-2026-55525PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/25/2026 Severity High CVE-2026-48169PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 08/07/2026 Severity High CVE-2026-55524PraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/05/2026 Severity High CVE-2026-55523PraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/05/2026 Severity High CVE-2026-55522PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/05/2026 Severity High CVE-2026-48168PraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch name Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 08/05/2026 Severity Critical CVE-2026-47419praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47418praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47417praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47416praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id} Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity Critical CVE-2026-47415praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47414praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOR Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47413praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity Critical CVE-2026-47412praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id} Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47411praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id} Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity Medium CVE-2026-47410praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity Critical CVE-2026-47409praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id} Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47408praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity Medium CVE-2026-47407PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity Critical CVE-2026-47406praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47405PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47399PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID Exploitation status Public exploit Fix Not confirmed Affected product P praisonai-platform Published 07/21/2026 Severity High CVE-2026-47398PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334 Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity High CVE-2026-47397PraisonAI has an Arbitrary File Write in Python API Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity High CVE-2026-47396PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity Critical CVE-2026-47395PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity Medium CVE-2026-47394PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity High CVE-2026-47393PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity Critical CVE-2026-47392PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity Critical CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity Critical CVE-2026-47390PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings Exploitation status Public exploit Fix Not confirmed Affected product P PraisonAI Published 07/21/2026 Severity Medium CVE-2026-61446PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61443PraisonAI before 1.6.78 Remote Code Execution via SkillTools Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61440PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61438PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61436PraisonAI before 4.6.78 Missing Webhook Signature Verification Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61435PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61433PraisonAI before 4.6.78 Code Injection via API deployment generator Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61430PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61427PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity Medium CVE-2026-60087PraisonAI before 1.6.78 Tool Approval Cache Bypass Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/15/2026 Severity Medium CVE-2026-60085PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 07/15/2026 Severity High CVE-2026-61447PraisonAI before 1.6.78 Remote Code Execution via CodeAgent Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity Critical CVE-2026-61445PraisonAI before 4.6.78 Arbitrary File Write and Command Execution Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity Critical CVE-2026-61442PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity High CVE-2026-61439PraisonAI before 4.6.78 Prompt Injection Defense Bypass Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity High CVE-2026-61429PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity High CVE-2026-61428PraisonAI AgentMail before 4.6.78 Message Injection via Webhook Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity Medium CVE-2026-61426PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity High CVE-2026-60090PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity Critical CVE-2026-60088PraisonAI before 4.6.78 Path Traversal via Custom Commands Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/11/2026 Severity Medium CVE-2026-61444PraisonAI before 4.6.78 Code Injection via f-string Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity Critical CVE-2026-61441PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity High CVE-2026-61437PraisonAI before 1.6.78 Remote Code Execution via tools.py Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity High CVE-2026-61434PraisonAI before 4.6.78 Allowlist Bypass via find -exec Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity High CVE-2026-61432PraisonAI FastContext before 1.6.78 Path Traversal Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity Medium CVE-2026-61431PraisonAI before 4.6.78 Path Traversal via ContextGatherer Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity Medium CVE-2026-60091PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity Medium CVE-2026-60089PraisonAI before 1.6.78 Path Traversal via config.toml Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity Medium CVE-2026-60086PraisonAI before 4.6.78 Prompt Injection Defense Bypass Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 07/10/2026 Severity Medium CVE-2026-44340PraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir` Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 05/08/2026 Severity High CVE-2026-44339PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 05/08/2026 Severity High CVE-2026-44338PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 05/08/2026 Severity High CVE-2026-44337PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 05/08/2026 Severity Medium CVE-2026-44336PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 05/08/2026 Severity Critical CVE-2026-44335SSRF bypass in PraisonAI Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 05/08/2026 Severity High CVE-2026-44334PraisonAI: Unauthenticated RCE via `tool_override.py` Exploitation status Not known exploited Fix YesAffected product P PraisonAI Published 05/08/2026 Severity High CVE-2026-41497Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI Exploitation status Public exploit Fix YesAffected product P PraisonAI Published 05/08/2026 Severity Critical