36 Total CVEs
36 AI Analyzed
0 CISA KEV
15 Critical

Profile

0% ended up actively exploited 0 of 36 added to CISA KEV
42% rated critical (CVSS 9.0+) 15 critical, 21 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

36 CVEs in the last 12 months

Products

  • system30
  • webhook request1
  • to themselves1

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-36 of 36 CVEs
CVE-2026-44339
Analyzed
8.6
Teams system

PraisonAI is a multi-agent teams system

2026-05-09
CVE-2026-44338
Analyzed
7.3
Teams system

PraisonAI is a multi-agent teams system

2026-05-10
CVE-2026-44336
Analyzed
9.6
Teams system

PraisonAI's MCP server fails to sanitize file paths in tool arguments, allowing unauthenticated attackers to perform arbitrary file writes and achieve...

2026-05-09
CVE-2026-44335
Analyzed
9.8
Teams system

PraisonAI contains a logical flaw in its URL checking mechanism that allows unauthenticated attackers to perform Server-Side Request Forgery (SSRF) at...

2026-05-09
CVE-2026-41497
Analyzed
9.8
Teams system

PraisonAI fails to validate commands in parse_mcp_command(), allowing unauthenticated attackers to execute arbitrary system commands via subprocesses.

2026-05-09
CVE-2026-41496
Analyzed
8.1
Teams system

PraisonAI is a multi-agent teams system

2026-05-09
CVE-2026-41485
Analyzed
7.7
Teams Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams

2026-04-24
CVE-2026-41405
Analyzed
7.5
Teams webhook request

OpenClaw before 2026

2026-04-29
CVE-2026-41323
Analyzed
8.1
Teams Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams

2026-04-24
CVE-2026-41068
Analyzed
7.7
Teams Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams

2026-04-24
CVE-2026-40868
Analyzed
8.1
Teams Multiple Products

Kyverno is a policy engine designed for cloud native platform engineering teams

2026-04-22
CVE-2026-40288
Analyzed
9.8
Teams system

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to a...

2026-04-14
CVE-2026-40287
Analyzed
8.4
Teams system

PraisonAI is a multi-agent teams system

2026-04-14
CVE-2026-40158
Analyzed
8.6
Teams system

PraisonAI is a multi-agent teams system

2026-04-11
CVE-2026-40156
Analyzed
7.8
Teams system

PraisonAI is a multi-agent teams system

2026-04-11
CVE-2026-40154
Analyzed
9.3
Teams system

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integri...

2026-04-10
CVE-2026-40150
Analyzed
7.7
Teams system

PraisonAIAgents is a multi-agent teams system

2026-04-10
CVE-2026-40149
Analyzed
7.9
Teams system

PraisonAI is a multi-agent teams system

2026-04-10
CVE-2026-40116
Analyzed
7.5
Teams system

PraisonAI is a multi-agent teams system

2026-04-11
CVE-2026-40113
Analyzed
8.4
Teams system

PraisonAI is a multi-agent teams system

2026-04-10
CVE-2026-40088
Analyzed
9.6
Teams system

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled in...

2026-04-10
CVE-2026-39891
Analyzed
8.8
Teams system

PraisonAI is a multi-agent teams system

2026-04-09
CVE-2026-39890
Analyzed
9.8
Teams system

PraisonAI versions prior to 4.5.115 are vulnerable to RCE via insecure YAML parsing, allowing execution of arbitrary JavaScript.

2026-04-09
CVE-2026-39889
Analyzed
7.5
Teams system

PraisonAI is a multi-agent teams system

2026-04-10
CVE-2026-39888
Analyzed
9.9
Teams system

PraisonAI versions prior to 1.5.115 contain a sandbox escape vulnerability in its Python code execution tool, allowing arbitrary code execution.

2026-04-09
CVE-2026-39355
Analyzed
9.9
Teams to themselves

A broken access control flaw in the Genealogy PHP application allows authenticated users to transfer ownership of arbitrary non-personal team workspac...

2026-04-08
CVE-2026-39305
Analyzed
9
Teams system

A Path Traversal vulnerability in the PraisonAI Action Orchestrator allows attackers to read or write arbitrary files on the host system.

2026-04-08
CVE-2026-34955
Analyzed
8.8
Teams system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34954
Analyzed
8.6
Teams system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34953
Analyzed
9.1
Teams system

A critical authentication bypass in PraisonAI's OAuthManager allows unauthenticated attackers to gain full access to all registered tools and agent ca...

2026-04-04
CVE-2026-34952
Analyzed
9.1
Teams system

PraisonAI Gateway prior to 4.5.97 lacks authentication for WebSocket and info endpoints. Attackers can enumerate AI agents and send arbitrary messages...

2026-04-04
CVE-2026-34938
Analyzed
10
Teams system

PraisonAI agents prior to 1.5.90 contain a sandbox bypass in the execute_code() function. Attackers can execute arbitrary OS commands on the host by b...

2026-04-04
CVE-2026-34937
Analyzed
7.8
Teams system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34936
Analyzed
7.7
Teams system

PraisonAI is a multi-agent teams system

2026-04-04
CVE-2026-34935
Analyzed
9.8
Teams system

PraisonAI CLI versions 4.5.15 through 4.5.68 are vulnerable to OS command injection via the --mcp argument. The argument is passed to the system shell...

2026-04-04
CVE-2026-34934
Analyzed
9.8
Teams system

PraisonAI prior to 4.5.90 is vulnerable to SQL injection in the get_all_user_threads function. Attackers can gain full database access by injecting ma...

2026-04-04