PraisonAI contains a remote code execution vulnerability in CodeAgent._execute_python() that allows attackers to execute arbitrary code via LLM prompt...
MervinPraison CVEs
66 high and critical vulnerabilities covered by CVE Brief since 2026-04-03, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
66 CVEs in the last 12 months
Products
- PraisonAI61
- praisonaiagents4
- praisonai-platform1
3 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
PraisonAI (praisonaiagents) before 1
PraisonAI is vulnerable to arbitrary file write and command execution via the AICoder component due to missing path and command validation in LLM tool...
PraisonAI contains a code injection vulnerability in its API module where unsanitized user input is passed to subprocess.Popen(), allowing arbitrary c...
PraisonAI Platform (praisonai-platform) before 0
PraisonAI versions before 4
PraisonAI (pip package praisonaiagents) before 1
PraisonAI before 4
PraisonAI before 4
PraisonAI versions before 4
PraisonAI before 1
PraisonAI versions before 1
PraisonAI AgentMail versions before 4
PraisonAI before 1
PraisonAI before 4
PraisonAI fails to validate the dimension argument in its knowledge-store backends, enabling SQL/CQL injection via specially crafted strings.
PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents...
PraisonAI versions prior to 4.6.58 suffer from missing authentication and authorization, allowing unauthenticated network clients to manipulate jobs a...
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-c...
PraisonAI fails to enforce API key or JWT authentication when environment variables are missing, allowing unauthenticated attackers to execute recipes...
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host...
An unauthenticated remote code execution vulnerability in PraisonAI allows attackers to execute arbitrary operating system commands via the /api/v1/ru...
PraisonAI versions prior to 4.6.59 are vulnerable to unauthenticated OS command injection via the /api/mcp/connect endpoint, allowing remote code exec...
PraisonAI agents fail to enforce authentication or origin validation on critical endpoints, allowing unauthenticated attackers to execute arbitrary to...
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_S...
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI versions prior to 4.6.40 contain a command injection vulnerability in its GitHub Actions workflow, allowing unauthenticated attackers to exe...
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI's MCP server fails to sanitize file paths in tool arguments, allowing unauthenticated attackers to perform arbitrary file writes and achieve...
PraisonAI contains a logical flaw in its URL checking mechanism that allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) at...
PraisonAI is a multi-agent teams system
PraisonAI fails to validate commands in parse_mcp_command(), allowing unauthenticated attackers to execute arbitrary system commands via subprocesses.
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cred...
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser...
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to a...
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integri...
PraisonAIAgents is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled in...
PraisonAI is a multi-agent teams system
PraisonAI versions prior to 4.5.115 are vulnerable to RCE via insecure YAML parsing, allowing execution of arbitrary JavaScript.
PraisonAI is a multi-agent teams system
PraisonAI versions prior to 1.5.115 contain a sandbox escape vulnerability in its Python code execution tool, allowing arbitrary code execution.
PraisonAI is a multi-agent teams system
A Path Traversal vulnerability in the PraisonAI Action Orchestrator allows attackers to read or write arbitrary files on the host system.
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
A critical authentication bypass in PraisonAI's OAuthManager allows unauthenticated attackers to gain full access to all registered tools and agent ca...
PraisonAI Gateway prior to 4.5.97 lacks authentication for WebSocket and info endpoints. Attackers can enumerate AI agents and send arbitrary messages...
PraisonAI agents prior to 1.5.90 contain a sandbox bypass in the execute_code() function. Attackers can execute arbitrary OS commands on the host by b...
PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system
PraisonAI CLI versions 4.5.15 through 4.5.68 are vulnerable to OS command injection via the --mcp argument. The argument is passed to the system shell...
PraisonAI prior to 4.5.90 is vulnerable to SQL injection in the get_all_user_threads function. Attackers can gain full database access by injecting ma...