Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Praisonai HIGH 7.5
CVE-2026-44340

PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack…

Fix: 4.6.37+
Fix from $1,950 2026-05-08
Praisonaiagents CRITICAL 9.8
CVE-2026-44335

PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by at…

Fix: 1.6.32+
Fix from $2,300 2026-05-08
Praisonai CRITICAL 9.6
CVE-2026-44336

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou…

Fix: 4.6.34+
Fix from $2,300 2026-05-08
Praisonaiagents HIGH 8.6
CVE-2026-44339

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved to…

Fix: 1.6.37 / 4.6.37+
Fix from $1,950 2026-05-08
Praisonai HIGH 8.4
CVE-2026-44334

PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISO…

Fix: 4.6.32+
Fix from $1,950 2026-05-08
Praisonai HIGH 7.3
CVE-2026-44338EPSS 29%

PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication d…

Fix: 4.6.34+
Fix from $1,950 2026-05-08
Praisonai MEDIUM 6.3
CVE-2026-44337

PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL-backed knowledge-store imple…

Fix: 4.6.34+
Fix from $1,600 2026-05-08
Praisonai CRITICAL 9.8
CVE-2026-41497

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg…

Fix: 4.6.9+
Fix from $2,300 2026-05-08
Praisonaiagents HIGH 8.1
CVE-2026-41496

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input v…

Fix: 1.6.9 / 4.6.9+
Fix from $1,950 2026-05-08
Praisonai CRITICAL 9.8
CVE-2026-40315

PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the ta…

Fix: 4.5.133+
Fix from $2,300 2026-04-14
Praisonai CRITICAL 9.1
CVE-2026-40313

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cre…

Fix: 4.5.140+
Fix from $2,300 2026-04-14
Praisonaiagents CRITICAL 9.8
CVE-2026-40288

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to …

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Praisonaiagents CRITICAL 9.1
CVE-2026-40289

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser…

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Praisonaiagents HIGH 8.4
CVE-2026-40287

PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import …

Fix: 1.5.140 / 4.5.139+
Fix from $1,950 2026-04-14
Praisonai HIGH 8.8
CVE-2026-40157

PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() withou…

Fix: 4.5.128+
Fix from $1,950 2026-04-10
Praisonai HIGH 7.8
CVE-2026-40156

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to …

Fix: 4.5.128+
Fix from $1,950 2026-04-10
Praisonai HIGH 7.8
CVE-2026-40158

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampolin…

Fix: 4.5.128+
Fix from $1,950 2026-04-10
Praisonaiagents MEDIUM 6.5
CVE-2026-40160

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncCli…

Fix: 1.5.128+
Fix from $1,600 2026-04-10
Praisonai MEDIUM 5.5
CVE-2026-40159

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers vi…

Fix: 4.5.128+
Fix from $1,600 2026-04-10
Praisonai CRITICAL 9.6
CVE-2026-40154

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integr…

Fix: 4.5.128+
Fix from $2,300 2026-04-09
Praisonaiagents MEDIUM 6.5
CVE-2026-40153

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every c…

Fix: 1.5.128+
Fix from $1,600 2026-04-09
Praisonai MEDIUM 5.3
CVE-2026-40151

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent name…

Fix: 4.5.128+
Fix from $1,600 2026-04-09
Praisonaiagents MEDIUM 5.3
CVE-2026-40152

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspac…

Fix: 1.5.128+
Fix from $1,600 2026-04-09
Praisonai CRITICAL 10.0
CVE-2026-40114

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL…

Fix: 4.5.128+
Fix from $2,300 2026-04-09
Praisonai HIGH 7.5
CVE-2026-40115

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into …

Fix: 4.5.128+
Fix from $1,950 2026-04-09
Praisonai HIGH 7.5
CVE-2026-40116

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from a…

Fix: 4.5.128+
Fix from $1,950 2026-04-09
Praisonaiagents HIGH 7.5
CVE-2026-40117

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesyst…

Fix: 1.5.128+
Fix from $1,950 2026-04-09
Praisonai HIGH 7.3
CVE-2026-40149

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unauthenticated modification of th…

Fix: 4.5.128+
Fix from $1,950 2026-04-09
Praisonai MEDIUM 6.5
CVE-2026-40148

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registry validates archive members a…

Fix: 4.5.128+
Fix from $1,600 2026-04-09
Praisonaiagents MEDIUM 6.5
CVE-2026-40150

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitra…

Fix: 1.5.128+
Fix from $1,600 2026-04-09