Praison
Praisonai: vulnerabilidades y CVE
Praisonai tiene 113 vulnerabilidades publicadas, 113 de ellas en los últimos 12 meses. 37 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE113
Últimos 12 meses113
Críticas37
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57141 | Crítica (9.8) | 0.74% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a… |
| CVE-2026-57140 | Crítica (9.4) | 0.64% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST… |
| CVE-2026-57139 | Crítica (9.8) | 0.75% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest()… |
| CVE-2026-57138 | Crítica (9.9) | 0.73% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small… |
| CVE-2026-57137 | Alta (8.8) | 0.51% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback.… |
| CVE-2026-57136 | Alta (8.8) | 0.55% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against… |
| CVE-2026-57135 | Alta (7.6) | 0.42% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and… |
| CVE-2026-57134 | Alta (8.2) | 0.41% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or… |
| CVE-2026-57133 | Alta (8.8) | 0.80% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and… |
| CVE-2026-57112 | Alta (8.3) | 0.22% | — | 15 sept 2026 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts… |
| CVE-2026-57145 | Crítica (9.1) | 0.54% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection,… |
| CVE-2026-57132 | Alta (8.2) | 0.51% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments… |
| CVE-2026-57131 | Crítica (9.8) | 0.97% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients… |
| CVE-2026-57127 | Crítica (9.8) | 0.90% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests… |
| CVE-2026-57124 | Crítica (9.8) | 1.0% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that… |
| CVE-2026-57122 | Alta (8.6) | 0.19% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and… |
| CVE-2026-57119 | Alta (7.5) | 0.53% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace… |
| CVE-2026-56839 | Alta (7.3) | 0.38% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment… |
| CVE-2026-57125 | Crítica (9.8) | 0.60% | — | 14 sept 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark… |
| CVE-2026-55539 | Alta (8.6) | 0.57% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable caller can submit jobs, read results, cancel runs, or delete… |
| CVE-2026-55536 | Crítica (9.1) | 0.52% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}.… |
| CVE-2026-55533 | Alta (8.2) | 0.49% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally… |
| CVE-2026-55532 | Alta (7.6) | 0.20% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to… |
| CVE-2026-55541 | Alta (8.8) | 0.48% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app() and _create_unified_app() do not install a credential… |
| CVE-2026-55540 | Alta (7.1) | 0.39% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point… |
| CVE-2026-55538 | Alta (7.3) | 0.45% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or… |
| CVE-2026-55537 | Alta (7.1) | 0.27% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except… |
| CVE-2026-55535 | Media (6.8) | 0.34% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker… |
| CVE-2026-55534 | Alta (8.6) | 0.45% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network… |
| CVE-2026-55531 | Media (6.5) | 0.45% | — | 25 ago 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize request but does not call _cleanup_sessions or enforce a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.