PraisonAI
MervinPraison · 129 CVEs
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
Sep 15, 2026
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
Sep 15, 2026
PraisonAI AgentOS exposes unauthenticated agent listing and invocation
Sep 15, 2026
PraisonAI MCPServer exposes unauthenticated HTTP tools/call
Sep 15, 2026
PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
Sep 15, 2026
PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
Sep 15, 2026
PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
Sep 15, 2026
PraisonAI codeMode sandbox escape via Function constructor
Sep 15, 2026
PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
Sep 15, 2026
PraisonAI AgentLoop onToolCall approval runs after tool execution
Sep 15, 2026
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
Sep 15, 2026
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
Sep 15, 2026
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
Sep 14, 2026
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
Sep 14, 2026
praisonai: Jobs API exposes agent-execution endpoints with no authentication
Sep 14, 2026
PraisonAI UI MCP connect endpoint allows unauthenticated local command execution
Sep 14, 2026
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (What…
Sep 14, 2026
praisonai: recipe serve auth middleware silently disables itself when no secret is set
Sep 14, 2026
PraisonAI Code agent tools fail open without a workspace boundary
Sep 14, 2026
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API
Sep 14, 2026
praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
Sep 14, 2026
PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
Sep 14, 2026
PraisonAI: SpiderTools redirect-target SSRF protection bypass
Sep 14, 2026
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
Sep 14, 2026
Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf…
Aug 25, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-57147 | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery | CRITICAL | 0.77% | Sep 15, 2026 |
| CVE-2026-57148 | praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) | CRITICAL | 0.64% | Sep 15, 2026 |
| CVE-2026-57140 | PraisonAI AgentOS exposes unauthenticated agent listing and invocation | CRITICAL | 0.64% | Sep 15, 2026 |
| CVE-2026-57139 | PraisonAI MCPServer exposes unauthenticated HTTP tools/call | CRITICAL | 0.75% | Sep 15, 2026 |
| CVE-2026-57133 | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining | HIGH | 0.80% | Sep 15, 2026 |
| CVE-2026-57135 | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients | HIGH | 0.42% | Sep 15, 2026 |
| CVE-2026-57134 | PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation | HIGH | 0.41% | Sep 15, 2026 |
| CVE-2026-57138 | PraisonAI codeMode sandbox escape via Function constructor | CRITICAL | 0.73% | Sep 15, 2026 |
| CVE-2026-57136 | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining | HIGH | 0.55% | Sep 15, 2026 |
| CVE-2026-57137 | PraisonAI AgentLoop onToolCall approval runs after tool execution | HIGH | 0.51% | Sep 15, 2026 |
| CVE-2026-57141 | PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool | CRITICAL | 0.74% | Sep 15, 2026 |
| CVE-2026-57112 | PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools | HIGH | 0.22% | Sep 15, 2026 |
| CVE-2026-57145 | PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation | CRITICAL | 0.54% | Sep 14, 2026 |
| CVE-2026-57132 | PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication | HIGH | 0.51% | Sep 14, 2026 |
| CVE-2026-57131 | praisonai: Jobs API exposes agent-execution endpoints with no authentication | CRITICAL | 0.97% | Sep 14, 2026 |
| CVE-2026-57124 | PraisonAI UI MCP connect endpoint allows unauthenticated local command execution | CRITICAL | 1.03% | Sep 14, 2026 |
| CVE-2026-57122 | PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots) | HIGH | 0.19% | Sep 14, 2026 |
| CVE-2026-57127 | praisonai: recipe serve auth middleware silently disables itself when no secret is set | CRITICAL | 0.90% | Sep 14, 2026 |
| CVE-2026-56839 | PraisonAI Code agent tools fail open without a workspace boundary | HIGH | 0.38% | Sep 14, 2026 |
| CVE-2026-57119 | PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API | HIGH | 0.53% | Sep 14, 2026 |
| CVE-2026-57126 | praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS | HIGH | 0.38% | Sep 14, 2026 |
| CVE-2026-57128 | PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint | MEDIUM | 0.25% | Sep 14, 2026 |
| CVE-2026-57115 | PraisonAI: SpiderTools redirect-target SSRF protection bypass | MEDIUM | 0.43% | Sep 14, 2026 |
| CVE-2026-57125 | PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass | CRITICAL | 0.60% | Sep 14, 2026 |
| CVE-2026-55536 | Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) | CRITICAL | 0.52% | Aug 25, 2026 |
Showing 1 to 25 of 129 CVEs