Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-40111 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string … Praisonaiagents 1.5.128+ Fix from $1,9502026-04-09 HIGH 8.1 CVE-2026-40113 PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run deploy --set-env-v… Praisonai 4.5.128+ Fix from $1,9502026-04-09 MEDIUM 6.1 CVE-2026-40112 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effect… Praisonai 4.5.128+ Fix from $1,6002026-04-09 CRITICAL 9.6 CVE-2026-40088 PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled i… Praisonai 4.5.121+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-39890 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files wit… Praisonai after 4.5.114 Fix from $2,3002026-04-08 HIGH 8.8 CVE-2026-39891 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that proces… Praisonai after 4.5.114 Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39889 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity withou… Praisonai after 4.5.114 Fix from $1,9502026-04-08 CRITICAL 9.9 CVE-2026-39888 PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", w… Praisonai 1.5.115+ Fix from $2,3002026-04-08 CRITICAL 10.0 CVE-2026-39305 PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an att… Praisonai after 4.5.112 Fix from $2,3002026-04-07 HIGH 8.1 CVE-2026-39307 PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File … Praisonai after 4.5.112 Fix from $1,9502026-04-07 HIGH 7.3 CVE-2026-39306 PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-controlled .praison tar archives w… Praisonai after 4.5.112 Fix from $1,9502026-04-07 HIGH 7.1 CVE-2026-39308 PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesyste… Praisonai after 4.5.112 Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-35615 PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collapses .. sequences, then checks… Praisonai 1.5.113+ Fix from $1,9502026-04-07 CRITICAL 10.0 CVE-2026-34955 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.r… Praisonai 4.5.97+ Fix from $2,3002026-04-04 CRITICAL 10.0 CVE-2026-34938 PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-l… Praisonaiagents 1.5.90+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-34937 PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-c… Praisonaiagents 1.5.90+ Fix from $2,3002026-04-03 CRITICAL 9.1 CVE-2026-34952 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent … Praisonai 4.5.97+ Fix from $2,3002026-04-03 CRITICAL 9.1 CVE-2026-34953 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal … Praisonai 4.5.97+ Fix from $2,3002026-04-03 HIGH 8.6 CVE-2026-34954 PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but per… Praisonaiagents 1.5.95+ Fix from $1,9502026-04-03 HIGH 7.5 CVE-2026-34939 PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python … Praisonai 4.5.90+ Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2026-34934 PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with u… Praisonai 4.5.90+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-34935 PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and… Praisonai 4.5.69+ Fix from $2,3002026-04-03 HIGH 7.7 CVE-2026-34936 PraisonAI is a multi-agent teams system. Prior to version 4.5.90, passthrough() and apassthrough() in praisonai accept a caller-controlled api_base p… Praisonai 4.5.90+ Fix from $1,9502026-04-03