PraisonAI
PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration.
Security Advisories for PraisonAI in pypi
High
about 1 month ago
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
pypi
praisonai
High
about 1 month ago
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
pypi
praisonai
Critical
about 1 month ago
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
pypi
praisonai
High
about 1 month ago
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
pypi
praisonai
High
about 1 month ago
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
pypi
praisonai
High
about 1 month ago
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
pypi
praisonai
High
about 1 month ago
PraisonAI Code agent tools fail open without a workspace boundary
pypi
praisonai
Critical
about 1 month ago
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
pypi
praisonai
High
about 1 month ago
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
pypi
praisonai
Critical
about 1 month ago
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
pypi
praisonai
High
about 1 month ago
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
pypi
praisonai
Critical
about 1 month ago
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
pypi
praisonai
Critical
about 1 month ago
praisonai: recipe serve auth middleware silently disables itself when no secret is set
pypi
praisonai
Critical
about 1 month ago
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
pypi
praisonaiagents, praisonai
High
about 1 month ago
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
pypi
praisonai
High
about 1 month ago
PraisonAI: Compute-bridged file tools allow shell command injection
pypi
praisonai
High
about 1 month ago
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
pypi
praisonai
High
about 1 month ago
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
pypi
praisonai
High
about 1 month ago
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
pypi
praisonai
High
about 1 month ago
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
pypi
praisonai
High
about 1 month ago
PraisonAI Slack app_mention bypasses configured user/channel authorization
pypi
praisonai
High
about 1 month ago
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
pypi
praisonai
High
about 1 month ago
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
pypi
praisonai, praisonaiagents
High
about 1 month ago
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
pypi
praisonai
High
about 1 month ago
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
pypi
praisonai
Critical
2 months ago
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
pypi
PraisonAI
High
2 months ago
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
pypi
PraisonAI
Critical
2 months ago
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
pypi
PraisonAI, praisonaiagents
Moderate
2 months ago
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
pypi
PraisonAI, praisonaiagents
Critical
2 months ago
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
pypi
PraisonAI
Critical
2 months ago
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
pypi
PraisonAI
Moderate
2 months ago
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
pypi
PraisonAI, praisonaiagents
High
2 months ago
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
pypi
PraisonAI
High
3 months ago
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
pypi
PraisonAI
High
3 months ago
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
pypi
PraisonAI, praisonaiagents
Critical
3 months ago
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
pypi
PraisonAI
Moderate
3 months ago
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
pypi
PraisonAI
High
3 months ago
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
pypi
praisonai
High
3 months ago
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
pypi
praisonaiagents, praisonai
Critical
3 months ago
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
pypi
praisonai
Critical
4 months ago
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
pypi
PraisonAI, praisonaiagents
Critical
4 months ago
PraisonAI has critical RCE via `type: job` workflow YAML
pypi
PraisonAI, praisonaiagents
High
4 months ago
PraisonAI Vulnerable to RCE via Automatic tools.py Import
pypi
PraisonAI, praisonaiagents
Moderate
4 months ago
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
pypi
PraisonAI
High
4 months ago
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
pypi
PraisonAI
Moderate
4 months ago
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
pypi
PraisonAI
Critical
4 months ago
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
pypi
PraisonAI
High
4 months ago
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
pypi
praisonai
Moderate
4 months ago
PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
pypi
PraisonAI
High
4 months ago
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
pypi
PraisonAI
Moderate
4 months ago
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
pypi
PraisonAI
High
4 months ago
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
pypi
PraisonAI
Moderate
4 months ago
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
pypi
PraisonAI
High
4 months ago
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
pypi
PraisonAI
High
4 months ago
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
pypi
PraisonAI
Moderate
4 months ago
PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
pypi
PraisonAI
High
4 months ago
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
pypi
praisonai
Critical
4 months ago
PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
pypi
praisonai
High
4 months ago
PraisonAI recipe registry publish path traversal allows out-of-root file write
pypi
PraisonAI
High
4 months ago
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
pypi
PraisonAI
Critical
4 months ago
PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator
pypi
PraisonAI
High
4 months ago
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
pypi
PraisonAI
Critical
4 months ago
PraisonAI Has Authentication Bypass via OAuthManager.validate_token()
pypi
praisonai
High
4 months ago
PraisonAI Has Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox
pypi
praisonai
Moderate
4 months ago
PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()
pypi
praisonai
Critical
4 months ago
PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`
pypi
praisonai
Critical
4 months ago
PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()
pypi
praisonai