Praison

Praisonai

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.43%
  • Veröffentlicht 08.05.2026 13:38:47
  • Zuletzt bearbeitet 08.05.2026 19:04:18

PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack flows route through validates each archive member's name for absolute paths, .. segments, and resolv...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 08.05.2026 13:37:09
  • Zuletzt bearbeitet 08.05.2026 22:16:33

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module globals and __main__ after it fails to match the declared tool list and the r...

Medienbericht Exploit
  • EPSS 26.8%
  • Veröffentlicht 08.05.2026 13:35:44
  • Zuletzt bearbeitet 08.05.2026 19:06:32

PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and tri...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 08.05.2026 13:33:51
  • Zuletzt bearbeitet 08.05.2026 19:07:00

PraisonAI is a multi-agent teams system. From version 2.4.1 to before version 4.6.34, PraisonAI exposes optional SQL/CQL-backed knowledge-store implementations that build table and index identifiers from unvalidated name and collection arguments. App...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 08.05.2026 13:32:33
  • Zuletzt bearbeitet 11.05.2026 20:25:46

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules.create, praisonai.rules.show, praisonai.rules.dele...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 08.05.2026 13:25:32
  • Zuletzt bearbeitet 08.05.2026 19:09:37

PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_TOOLS=true in two files (tool_resolver.py, api/call.py). A third import sink in prais...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 08.05.2026 13:23:36
  • Zuletzt bearbeitet 08.05.2026 19:10:22

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables like bash, python, or /bin/sh...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 08.05.2026 13:19:10
  • Zuletzt bearbeitet 09.05.2026 00:16:27

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/My...

Medienbericht
  • EPSS 0.31%
  • Veröffentlicht 14.04.2026 03:10:23
  • Zuletzt bearbeitet 20.04.2026 17:39:52

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage vector caused by using actions/checkout without setting persist-credentials: false. B...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 14.04.2026 03:05:05
  • Zuletzt bearbeitet 20.04.2026 17:46:45

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a...