Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-44340 PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack… Praisonai 4.6.37+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-44335 PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by at… Praisonaiagents 1.6.32+ Fix from $2,3002026-05-08 CRITICAL 9.6 CVE-2026-44336 PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou… Praisonai 4.6.34+ Fix from $2,3002026-05-08 HIGH 8.6 CVE-2026-44339 PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved to… Praisonaiagents 1.6.37 / 4.6.37+ Fix from $1,9502026-05-08 HIGH 8.4 CVE-2026-44334 PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISO… Praisonai 4.6.32+ Fix from $1,9502026-05-08 HIGH 7.3 CVE-2026-44338EPSS 29% PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication d… Praisonai 4.6.34+ Fix from $1,9502026-05-08 MEDIUM 6.3 CVE-2026-44337 PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL-backed knowledge-store imple… Praisonai 4.6.34+ Fix from $1,6002026-05-08 CRITICAL 9.8 CVE-2026-41497 PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg… Praisonai 4.6.9+ Fix from $2,3002026-05-08 HIGH 8.1 CVE-2026-41496 PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input v… Praisonaiagents 1.6.9 / 4.6.9+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-40315 PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the ta… Praisonai 4.5.133+ Fix from $2,3002026-04-14 CRITICAL 9.1 CVE-2026-40313 PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cre… Praisonai 4.5.140+ Fix from $2,3002026-04-14 CRITICAL 9.8 CVE-2026-40288 PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to … Praisonaiagents 1.5.140 / 4.5.139+ Fix from $2,3002026-04-14 CRITICAL 9.1 CVE-2026-40289 PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser… Praisonaiagents 1.5.140 / 4.5.139+ Fix from $2,3002026-04-14 HIGH 8.4 CVE-2026-40287 PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import … Praisonaiagents 1.5.140 / 4.5.139+ Fix from $1,9502026-04-14 HIGH 8.8 CVE-2026-40157 PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() withou… Praisonai 4.5.128+ Fix from $1,9502026-04-10 HIGH 7.8 CVE-2026-40156 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to … Praisonai 4.5.128+ Fix from $1,9502026-04-10 HIGH 7.8 CVE-2026-40158 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampolin… Praisonai 4.5.128+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-40160 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncCli… Praisonaiagents 1.5.128+ Fix from $1,6002026-04-10 MEDIUM 5.5 CVE-2026-40159 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers vi… Praisonai 4.5.128+ Fix from $1,6002026-04-10 CRITICAL 9.6 CVE-2026-40154 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integr… Praisonai 4.5.128+ Fix from $2,3002026-04-09 MEDIUM 6.5 CVE-2026-40153 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every c… Praisonaiagents 1.5.128+ Fix from $1,6002026-04-09 MEDIUM 5.3 CVE-2026-40151 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent name… Praisonai 4.5.128+ Fix from $1,6002026-04-09 MEDIUM 5.3 CVE-2026-40152 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspac… Praisonaiagents 1.5.128+ Fix from $1,6002026-04-09 CRITICAL 10.0 CVE-2026-40114 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL… Praisonai 4.5.128+ Fix from $2,3002026-04-09 HIGH 7.5 CVE-2026-40115 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into … Praisonai 4.5.128+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-40116 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from a… Praisonai 4.5.128+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-40117 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesyst… Praisonaiagents 1.5.128+ Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-40149 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unauthenticated modification of th… Praisonai 4.5.128+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-40148 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registry validates archive members a… Praisonai 4.5.128+ Fix from $1,6002026-04-09 MEDIUM 6.5 CVE-2026-40150 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitra… Praisonaiagents 1.5.128+ Fix from $1,6002026-04-09