Skip to content
Threat Feed

Product

PraisonAI

10 briefs RSS
high advisory

Authentication Bypass in PraisonAI Call API via Host Header Spoofing (CVE-2026-61435)

PraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability in the Call API agent invocation endpoints when PRAISONAI_CALL_AUTH=disabled is configured, allowing an unauthenticated attacker to remotely list and invoke registered agents by sending a spoofed 'Host: 127.0.0.1' HTTP header.

PraisonAI authentication-bypass vulnerability web-application rce-potential
1r 2t 1c
high advisory

PraisonAI web_crawl Tool Vulnerable to DNS Rebinding SSRF (CVE-2026-61430)

PraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) within its web_crawl tool, allowing attackers to bypass hostname validation using DNS rebinding and retrieve sensitive internal HTTP response bodies from private or loopback services.

PraisonAI +1 ssrf dns-rebinding vulnerability web-application code-injection remote-code-execution python cve +4
1r 3t 1c
high advisory

Insecure Default Configuration in PraisonAI Allows Unauthenticated Access

An insecure default configuration in PraisonAI before version 1.7.3 allows unauthenticated attackers to exploit CVE-2026-61426 by reading sensitive agent instructions and system prompts via the `/api/agents` endpoint and invoking agents without authentication through the `/api/chat` endpoint, leading to unauthorized information disclosure and potential control over AI functionalities.

PraisonAI vulnerability web-application insecure-configuration cve
2r 3t 1c
high advisory

CVE-2026-61434: PraisonAI Shell Command Allowlist Bypass

PraisonAI versions prior to 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to use find's built-in -exec, -execdir, and -delete actions to execute restricted commands, read or delete files, or run non-allowlisted binaries, bypassing existing shell metacharacter filters, which can lead to arbitrary command execution and impact system integrity.

PraisonAI vulnerability rce allowlist-bypass cve
1r 3t 1c 2i
high advisory

PraisonAI Symlink Extraction Bypass Vulnerability

PraisonAI versions 2.7.2 through 4.6.35 are vulnerable to an arbitrary file write due to improper validation of symlinks during archive extraction, affecting `recipe pull`, `recipe publish`, and `recipe unpack` flows.

PraisonAI symlink arbitrary file write path traversal attack.persistence attack.privilege_escalation
2r 2t 1c
critical advisory

PraisonAI Workflow Engine Vulnerability CVE-2026-40288

PraisonAI versions before 4.5.139 and praisonaiagents versions before 1.5.140 are vulnerable to arbitrary command execution via untrusted YAML files processed by the workflow engine.

PraisonAI +1 yaml code-execution cve-2026-40288
2r 1t 1c
high advisory

PraisonAI Arbitrary Code Execution via Malicious tools.py Import

PraisonAI versions 4.5.138 and earlier are vulnerable to arbitrary code execution due to the automatic import and execution of a `tools.py` file from the current working directory, allowing attackers to execute arbitrary Python code.

PraisonAI rce python
2r 1t 1i
critical advisory

PraisonAI Arbitrary File Write via Path Traversal in Recipe Unpack

A critical path traversal vulnerability in PraisonAI's `recipe unpack` allows arbitrary file writes by unpacking a malicious bundle, leading to potential privilege escalation and persistence.

PraisonAI path-traversal arbitrary-file-write
2r 2t 1c
high advisory

PraisonAI Cloud Run Environment Variable Injection Vulnerability (CVE-2026-40113)

PraisonAI versions before 4.5.128 are vulnerable to arbitrary environment variable injection in Google Cloud Run deployments due to insufficient input validation when constructing the `--set-env-vars` argument, potentially leading to privilege escalation.

PraisonAI cve-2026-40113 cloud environment variable injection privilege escalation
2r 1t 1c
high advisory

PraisonAI Arbitrary Code Execution Vulnerability (CVE-2026-40156)

PraisonAI versions before 4.5.128 are vulnerable to arbitrary code execution due to the automatic loading and execution of a 'tools.py' file from the current working directory without proper validation or user consent, potentially allowing attackers to execute malicious code by placing a rogue file in a PraisonAI execution directory.

PraisonAI cve-2026-40156 code-execution
2r 1t 1c