Praison

Praisonaiagents

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.36%
  • Veröffentlicht 08.05.2026 13:37:09
  • Zuletzt bearbeitet 08.05.2026 22:16:33

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module globals and __main__ after it fails to match the declared tool list and the r...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 08.05.2026 13:26:48
  • Zuletzt bearbeitet 08.05.2026 19:09:07

PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32.

Exploit
  • EPSS 0.35%
  • Veröffentlicht 08.05.2026 13:19:10
  • Zuletzt bearbeitet 09.05.2026 00:16:27

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/My...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 14.04.2026 03:05:05
  • Zuletzt bearbeitet 20.04.2026 17:46:45

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 14.04.2026 03:00:21
  • Zuletzt bearbeitet 20.04.2026 17:47:03

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. When praisonai workflow run <file....

Exploit
  • EPSS 0.25%
  • Veröffentlicht 14.04.2026 02:55:38
  • Zuletzt bearbeitet 20.04.2026 17:47:31

PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_fro...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 10.04.2026 16:59:09
  • Zuletzt bearbeitet 20.04.2026 20:17:49

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an in...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.04.2026 22:16:36
  • Zuletzt bearbeitet 20.04.2026 18:33:29

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via _validate_path(), but passes the pattern parameter directly to Path.glob() without a...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 09.04.2026 22:16:36
  • Zuletzt bearbeitet 20.04.2026 19:55:29

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despi...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 09.04.2026 22:16:35
  • Zuletzt bearbeitet 17.04.2026 18:23:42

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path parameter. Unlike file_tools.read_file which enforces work...