Praisonaiagents
This hub aggregates every CVE we track for Praisonaiagents, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
5
Critical
9
High
0
In CISA KEV
Severity distribution
HIGH9MEDIUM5CRITICAL5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
13
3
0
2
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Praisonaiagents.
- CVE-2026-55522PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code7.8
- CVE-2026-47395PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context5.5
- CVE-2026-47390PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings5.5
- CVE-2026-44339PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute8.6
- CVE-2026-44335SSRF bypass in PraisonAI9.8
- CVE-2026-41496PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)8.1
- CVE-2026-40289PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions9.1
- CVE-2026-40288PraisonAI: Critical RCE via `type: job` workflow YAML9.8
- CVE-2026-40287PraisonAI has RCE via Automatic tools.py Import8.4
- CVE-2026-40160PraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback6.5
- CVE-2026-40153PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool7.4
- CVE-2026-40152PraisonAIAgents has a Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary5.3
- CVE-2026-40150PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool7.7
- CVE-2026-40117PraisonAIAgents Affected by Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate6.2
- CVE-2026-40111PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)8.8
Product normalization is registry-driven with AI assist and human review. How it works