66 Total CVEs
66 AI Analyzed
0 CISA KEV
26 Critical

Profile

0% ended up actively exploited 0 of 66 added to CISA KEV
39% rated critical (CVSS 9.0+) 26 critical, 40 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

66 CVEs in the last 12 months

Products

  • PraisonAI61
  • praisonaiagents4
  • praisonai-platform1

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-66 of 66 CVEs
CVE-2026-61447
Analyzed
10
MervinPraison PraisonAI

PraisonAI contains a remote code execution vulnerability in CodeAgent._execute_python() that allows attackers to execute arbitrary code via LLM prompt...

2026-07-12
Full analysis →
CVE-2026-61445
Analyzed
9.9
MervinPraison PraisonAI

PraisonAI is vulnerable to arbitrary file write and command execution via the AICoder component due to missing path and command validation in LLM tool...

2026-07-12
Full analysis →
CVE-2026-61444
Analyzed
9.1
MervinPraison PraisonAI

PraisonAI contains a code injection vulnerability in its API module where unsanitized user input is passed to subprocess.Popen(), allowing arbitrary c...

2026-07-11
Full analysis →
CVE-2026-60090
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI fails to validate the dimension argument in its knowledge-store backends, enabling SQL/CQL injection via specially crafted strings.

2026-07-12
Full analysis →
CVE-2026-57132
Analyzed
8.2
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents...

2026-09-15
Full analysis →
CVE-2026-57131
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI versions prior to 4.6.58 suffer from missing authentication and authorization, allowing unauthenticated network clients to manipulate jobs a...

2026-09-15
Full analysis →
CVE-2026-57130
Analyzed
8.1
MervinPraison praisonaiagents

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-c...

2026-09-15
Full analysis →
CVE-2026-57127
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI fails to enforce API key or JWT authentication when environment variables are missing, allowing unauthenticated attackers to execute recipes...

2026-09-15
Full analysis →
CVE-2026-57126
Analyzed
8.5
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host...

2026-09-15
Full analysis →
CVE-2026-57125
Analyzed
9.8
MervinPraison PraisonAI

An unauthenticated remote code execution vulnerability in PraisonAI allows attackers to execute arbitrary operating system commands via the /api/v1/ru...

2026-09-15
Full analysis →
CVE-2026-57124
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI versions prior to 4.6.59 are vulnerable to unauthenticated OS command injection via the /api/mcp/connect endpoint, allowing remote code exec...

2026-09-15
Full analysis →
CVE-2026-57123
Analyzed
9.8
MervinPraison praisonaiagents

PraisonAI agents fail to enforce authentication or origin validation on critical endpoints, allowing unauthenticated attackers to execute arbitrary to...

2026-09-15
Full analysis →
CVE-2026-57122
Analyzed
8.6
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_S...

2026-09-15
Full analysis →
CVE-2026-48168
Analyzed
10
MervinPraison PraisonAI

PraisonAI versions prior to 4.6.40 contain a command injection vulnerability in its GitHub Actions workflow, allowing unauthenticated attackers to exe...

2026-08-06
Full analysis →
CVE-2026-44336
Analyzed
9.6
MervinPraison PraisonAI

PraisonAI's MCP server fails to sanitize file paths in tool arguments, allowing unauthenticated attackers to perform arbitrary file writes and achieve...

2026-05-09
Full analysis →
CVE-2026-44335
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI contains a logical flaw in its URL checking mechanism that allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) at...

2026-05-09
Full analysis →
CVE-2026-41497
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI fails to validate commands in parse_mcp_command(), allowing unauthenticated attackers to execute arbitrary system commands via subprocesses.

2026-05-09
Full analysis →
CVE-2026-40313
Analyzed
9.1
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cred...

2026-04-14
Full analysis →
CVE-2026-40289
Analyzed
9.1
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser...

2026-04-14
Full analysis →
CVE-2026-40288
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to a...

2026-04-14
Full analysis →
CVE-2026-40154
Analyzed
9.3
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integri...

2026-04-10
Full analysis →
CVE-2026-40088
Analyzed
9.6
MervinPraison PraisonAI

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled in...

2026-04-10
Full analysis →
CVE-2026-39890
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI versions prior to 4.5.115 are vulnerable to RCE via insecure YAML parsing, allowing execution of arbitrary JavaScript.

2026-04-09
Full analysis →
CVE-2026-39888
Analyzed
9.9
MervinPraison praisonaiagents

PraisonAI versions prior to 1.5.115 contain a sandbox escape vulnerability in its Python code execution tool, allowing arbitrary code execution.

2026-04-09
Full analysis →
CVE-2026-39305
Analyzed
9
MervinPraison PraisonAI

A Path Traversal vulnerability in the PraisonAI Action Orchestrator allows attackers to read or write arbitrary files on the host system.

2026-04-08
Full analysis →
CVE-2026-34953
Analyzed
9.1
MervinPraison PraisonAI

A critical authentication bypass in PraisonAI's OAuthManager allows unauthenticated attackers to gain full access to all registered tools and agent ca...

2026-04-04
Full analysis →
CVE-2026-34952
Analyzed
9.1
MervinPraison PraisonAI

PraisonAI Gateway prior to 4.5.97 lacks authentication for WebSocket and info endpoints. Attackers can enumerate AI agents and send arbitrary messages...

2026-04-04
Full analysis →
CVE-2026-34938
Analyzed
10
MervinPraison PraisonAI

PraisonAI agents prior to 1.5.90 contain a sandbox bypass in the execute_code() function. Attackers can execute arbitrary OS commands on the host by b...

2026-04-04
Full analysis →
CVE-2026-34935
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI CLI versions 4.5.15 through 4.5.68 are vulnerable to OS command injection via the --mcp argument. The argument is passed to the system shell...

2026-04-04
Full analysis →
CVE-2026-34934
Analyzed
9.8
MervinPraison PraisonAI

PraisonAI prior to 4.5.90 is vulnerable to SQL injection in the get_all_user_threads function. Attackers can gain full database access by injecting ma...

2026-04-04
Full analysis →