Where
-Infinity
0

PraisonAI PraisonAIPraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

Risk 51
Severity
7.5
First published (updated )

PraisonAI praisonaiPraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targets

Risk 46
Severity
7.7
First published (updated )

PraisonAI PraisonAIPraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

Risk 68
Severity
7.8
First published (updated )

PraisonAI praisonaiagentsPraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery

Risk 76
Severity
8.6
First published (updated )

PraisonAI PraisonAI PlatformPraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PraisonAI praisonaiPraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing

Risk 57
Severity
8.8
First published (updated )

PraisonAI praisonaiPraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl

Risk 55
Severity
8.4
First published (updated )

PraisonAI praisonaiPraisonAI before 4.6.78 Authentication Bypass via HTTP-stream

Risk 51
Severity
6.9
First published (updated )

PraisonAI praisonaiPraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults

Risk 65
Severity
8.8
First published (updated )

PraisonAI praisonaiPraisonAI before 4.6.78 SQL/CQL Injection via vector dimension

Risk 86
Severity
9.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PraisonAI praisonaiPraisonAI before 4.6.78 Code Injection via f-string

Risk 75
Severity
9.4
First published (updated )

PraisonAI praisonaiPraisonAI before 4.6.78 Allowlist Bypass via find -exec

Risk 79
Severity
8.7
First published (updated )

PraisonAI praisonaiPraisonAI before 4.6.78 Path Traversal via ContextGatherer

Risk 36
Severity
6.8
First published (updated )

PraisonAI praisonaiagentsPraisonAI FastContext before 1.6.78 Path Traversal

Risk 38
Severity
6.9
First published (updated )

PraisonAI praisonaiPraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url

Risk 44
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PraisonAI praisonaiPraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update

Risk 26
Severity
5.3
First published (updated )

PraisonAI PraisonAI MultiAgentMonitorPraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor

Risk 79
Severity
8.7
First published (updated )

PraisonAI praisonaiPraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

Risk 61
Severity
8.6
First published (updated )

PraisonAI praisonaiPraisonAI - Information Disclosure via Shared MultiAgentLedger State

Risk 40
Severity
7.1
First published (updated )

PraisonAI praisonaiPraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override

Risk 79
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PraisonAI praisonaiPraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching

Risk 36
Severity
6.8
First published (updated )

CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure

First published (updated )
Social
reddit

PraisonAI praisonaiPraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`

Risk 47
Severity
8.7
First published (updated )

PraisonAI praisonaiPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

Risk 54
Severity
7.3
First published (updated )

PraisonAI praisonaiPraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries

Risk 46
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

PraisonAI PraisonAI MCPPraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection

Risk 80
Severity
9.4
First published (updated )

PraisonAI praisonaiPraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence

Risk 66
Severity
9.1
First published (updated )

PraisonAI praisonaiPraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

Risk 66
Severity
9.1
First published (updated )

PraisonAI praisonaiPraisonAI: Critical RCE via `type: job` workflow YAML

Risk 86
Severity
9.8
First published (updated )

PraisonAI praisonaiPraisonAI has RCE via Automatic tools.py Import

Risk 74
Severity
8.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203