Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Praisonaiagents HIGH 8.8
CVE-2026-40111

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string …

Fix: 1.5.128+
Fix from $1,950 2026-04-09
Praisonai HIGH 8.1
CVE-2026-40113

PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run deploy --set-env-v…

Fix: 4.5.128+
Fix from $1,950 2026-04-09
Praisonai MEDIUM 6.1
CVE-2026-40112

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effect…

Fix: 4.5.128+
Fix from $1,600 2026-04-09
Praisonai CRITICAL 9.6
CVE-2026-40088

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled i…

Fix: 4.5.121+
Fix from $2,300 2026-04-09
Praisonai CRITICAL 9.8
CVE-2026-39890

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files wit…

Fix: after 4.5.114
Fix from $2,300 2026-04-08
Praisonai HIGH 8.8
CVE-2026-39891

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that proces…

Fix: after 4.5.114
Fix from $1,950 2026-04-08
Praisonai HIGH 7.5
CVE-2026-39889

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity withou…

Fix: after 4.5.114
Fix from $1,950 2026-04-08
Praisonai CRITICAL 9.9
CVE-2026-39888

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", w…

Fix: 1.5.115+
Fix from $2,300 2026-04-08
Praisonai CRITICAL 10.0
CVE-2026-39305

PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an att…

Fix: after 4.5.112
Fix from $2,300 2026-04-07
Praisonai HIGH 8.1
CVE-2026-39307

PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File …

Fix: after 4.5.112
Fix from $1,950 2026-04-07
Praisonai HIGH 7.3
CVE-2026-39306

PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-controlled .praison tar archives w…

Fix: after 4.5.112
Fix from $1,950 2026-04-07
Praisonai HIGH 7.1
CVE-2026-39308

PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesyste…

Fix: after 4.5.112
Fix from $1,950 2026-04-07
Praisonai HIGH 7.5
CVE-2026-35615

PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collapses .. sequences, then checks…

Fix: 1.5.113+
Fix from $1,950 2026-04-07
Praisonai CRITICAL 10.0
CVE-2026-34955

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.r…

Fix: 4.5.97+
Fix from $2,300 2026-04-04
Praisonaiagents CRITICAL 10.0
CVE-2026-34938

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-l…

Fix: 1.5.90+
Fix from $2,300 2026-04-03
Praisonaiagents CRITICAL 9.8
CVE-2026-34937

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-c…

Fix: 1.5.90+
Fix from $2,300 2026-04-03
Praisonai CRITICAL 9.1
CVE-2026-34952

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent …

Fix: 4.5.97+
Fix from $2,300 2026-04-03
Praisonai CRITICAL 9.1
CVE-2026-34953

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal …

Fix: 4.5.97+
Fix from $2,300 2026-04-03
Praisonaiagents HIGH 8.6
CVE-2026-34954

PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but per…

Fix: 1.5.95+
Fix from $1,950 2026-04-03
Praisonai HIGH 7.5
CVE-2026-34939

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python …

Fix: 4.5.90+
Fix from $1,950 2026-04-03
Praisonai CRITICAL 9.8
CVE-2026-34934

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with u…

Fix: 4.5.90+
Fix from $2,300 2026-04-03
Praisonai CRITICAL 9.8
CVE-2026-34935

PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and…

Fix: 4.5.69+
Fix from $2,300 2026-04-03
Praisonai HIGH 7.7
CVE-2026-34936

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a caller-controlled api_base p…

Fix: 4.5.90+
Fix from $1,950 2026-04-03