These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-61426 involves PraisonAI, a tool that offers AI functionalities. The vulnerability arises from its insecure default configuration, which binds to all interfaces without requiring an API key and with wildcard CORS enabled. This setup allows unauthenticated attackers to access certain endpoints, such as GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents.
CVE-2026-61445 is a critical vulnerability in PraisonAI before version 4.6.78, affecting the AICoder component. The vulnerability is characterized by arbitrary file write and command execution attacks due to missing path validation and command sanitization in LLM tool calls. Attackers can exploit this by injecting malicious prompts through the chat interface, allowing them to write files to arbitrary file [truncated]
CVE-2026-61427 is a vulnerability in PraisonAI before version 4.6.78. The MCP HTTP-stream transport is exposed without authentication by default. The CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer checks when an API key is configured. An unauthenticated client can initialize a session, enumerate available tools, and invoke tools without an API key. The dispatcher [truncated]
CVE-2026-61440: PraisonAI Platform before 0.1.9 has a vulnerability that allows workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. This is due to a lack of proper authorization for label and issue-label mutations. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Users of PraisonAI Platform before version 0.1.9 should be awar [truncated]
CVE-2026-60091 is a medium-severity vulnerability in PraisonAI before version 4.6.78, allowing unauthenticated server-side request forgery via the Jobs API /api/v1/runs endpoint. The vulnerability is caused by the webhook_url parameter being validated at request time but re-resolved at connection time, enabling attackers to use DNS rebinding for a blind SSRF attack on internal services.
CVE-2026-60086 is a medium-severity vulnerability in PraisonAI before version 4.6.78, allowing attackers to bypass the prompt injection defense mechanism. The defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. This allows attackers to craft HIGH-level threat injections that can bypass the defense and reach the model. Security teams and ad [truncated]
PraisonAI's API deployment generator embeds unescaped YAML fields into Python source, allowing for code injection. The generator copies `deploy.api.host` from `agents.yaml` directly into generated Python source without safe literal encoding. A malicious PraisonAI project can set that host value to a Python expression splice; when an operator runs the API deploy flow, the generated server source compiles a [truncated]
CVE-2026-61435 is a vulnerability in PraisonAI's n8n/call agent invocation API. The patched `PRAISONAI_CALL_AUTH=disabled` safeguard can be bypassed with a spoofed `Host: 127.0.0.1` header, allowing an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled. This vulnerability affects PraisonAI deployments, particularly those with expose [truncated]
CVE-2026-61431 is a path traversal vulnerability in PraisonAI's ContextGatherer component. The vulnerability occurs due to insufficient validation of include paths in .praisoncontext and .praisoninclude files. This allows attackers to supply absolute paths or parent directory traversal sequences, enabling them to read arbitrary files outside the workspace and include their contents in the generated contex [truncated]
CVE-2026-60088 is a path traversal vulnerability in PraisonAI before version 4.6.78. The vulnerability allows attackers to read files outside the workspace by including path traversal sequences or absolute paths in project command files. This could potentially lead to the exfiltration of sensitive information. Users of PraisonAI before version 4.6.78 should be aware of this vulnerability and take steps to [truncated]
CVE-2026-61443 debrief: PraisonAI SkillTools executes scripts without path containment validation, allowing for potential arbitrary script execution via LLM-directed calls. This vulnerability affects PraisonAI deployments, which defenders should assess for exposure and prioritize patching to prevent potential script execution. The `@require_approval` decorator can be bypassed via YAML `approve:` for high- [truncated]
CVE-2026-61437 is a high-severity vulnerability in PraisonAI (pip package praisonaiagents) before version 1.6.78. The vulnerability is caused by an unsafe dynamic module loading mechanism in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). This allows an attacker to execute arbitrary Python code with the workflow runner's privileges when the workflow is exec [truncated]
A path traversal vulnerability exists in PraisonAI (praisonaiagents) before 1.6.78 in the FastContext feature (praisonaiagents.context.fast). The vulnerability allows attackers to read, search, and enumerate files outside the intended workspace directory, potentially leading to unauthorized access to sensitive information. Users of PraisonAI (praisonaiagents) before version 1.6.78 should apply the patch t [truncated]
The PraisonAI plugin manager is vulnerable to arbitrary code execution due to loading and executing `.py` files from `.praisonai/plugins/` directories without verification or sandboxing. This allows an attacker who can write to the plugins directory to achieve code execution when the plugin system initializes. The vulnerability is caused by the plugin manager's lack of code signing, integrity verification [truncated]
CVE-2026-61447 is a remote code execution vulnerability in PraisonAI before version 1.6.78. The vulnerability is caused by the CodeAgent._execute_python() function executing LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host sy [truncated]
PraisonAI's human-in-the-loop tool approval mechanism is vulnerable to cache bypass, allowing potentially dangerous tool invocations with arbitrary arguments without proper review. This vulnerability exists due to the ApprovalRegistry.is_already_approved function in src/praisonai-agents/praisonaiagents/approval/registry.py, which returns True if a tool name is present in a per-run context set, without con [truncated]
PraisonAI's `web_crawl` agent tool is vulnerable to a DNS rebinding bypass in its SSRF protection, allowing internal response disclosure. This occurs because the `_is_safe_crawl_url()` function resolves the hostname and rejects private/loopback/link-local IPs at validation time, but the fetch backend re-resolves the hostname at connection time. A DNS-rebinding domain can return a public IP during validati [truncated]
CVE-2026-60089 is a path traversal vulnerability in PraisonAI, a pip package for AI agents. Versions before 1.6.78 are affected. The vulnerability allows an untrusted checked-out project to overwrite files outside the project root with the privileges of the user running PraisonAI. This is possible because PraisonAI automatically loads defaults from a project-local .praisonai/config.toml file and does not [truncated]
CVE-2026-61439 is a high-severity vulnerability in PraisonAI versions before 4.6.78. The vulnerability is caused by a prompt injection defense misconfiguration, where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. This could enable attackers to submit single-vector prompt injection attacks, such as instruction overrides or financial manipulation, [truncated]
CVE-2026-62176 is a critical vulnerability in PraisonAI, a multi-agent teams system, due to code injection via f-string interpolation in the Deploy API Server Generation. An attacker controlling the `agents_file` parameter can inject arbitrary Python code. The issue was patched in version 4.6.78. This vulnerability requires immediate attention from security teams, DevOps teams, and administrators managing [truncated]
CVE-2026-61444 is a critical code injection vulnerability in PraisonAI versions before 4.6.78. The vulnerability exists in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen(). This vulnerability has a CVSS score of 9.4 and is consider [truncated]
CVE-2026-62179 is a vulnerability in PraisonAI's platform where members can delete issue dependencies created by the owner through their own related issues due to improper authorization checks. This issue exists in versions prior to 0.1.9. The vulnerability has a CVSS score of 6.5 and is considered medium severity. Affected product deployments should be reviewed for exposure, and defenders should prioriti [truncated]
CVE-2026-61441 is a high-severity vulnerability in PraisonAI Platform versions before 0.1.9. It allows members to bypass owner/admin authorization and remove owner-created issue dependencies by targeting related member-owned issue endpoints. This occurs because permission is validated against the member-owned issue's owner. Users of PraisonAI Platform versions before 0.1.9 should apply the patch to preven [truncated]
CVE-2026-61436 is a vulnerability in PraisonAI's AgentMail webhook mode that allows forged unsigned message.received events to be accepted and agents to be invoked. The affected boundary is webhook authenticity, and the issue arises from the lack of verification of AgentMail's Svix webhook signatures. This vulnerability impacts PraisonAI users who utilize the AgentMail webhook mode, as it could allow atta [truncated]
CVE-2026-55539 is a high-severity vulnerability in PraisonAI, a multi-agent teams system, prior to version 4.6.51. The Jobs API create_app function was found to be unprotected, allowing unauthorized access to submit jobs, read results, cancel runs, or delete jobs using operator credentials. The issue was addressed in version 4.6.58 with the addition of PRAISONAI_JOBS_API_KEY middleware for Authorization or X-API-Key.
CVE-2026-55533 is a high-severity vulnerability in PraisonAI, a multi-agent teams system. The issue allows unauthenticated POST /v1/recipes/run requests despite authentication being enabled. This vulnerability is fixed in version 4.6.58. Defenders should assess exposure, verify authentication configurations, and apply the fixed version to mitigate potential operational impacts. The vulnerability's high se [truncated]
CVE-2026-55532 is a high-severity vulnerability in PraisonAI, a multi-agent teams system. The issue, fixed in version 4.6.58, allows an attacker to bypass security checks and invoke tools without an API key, potentially leading to file writes and persistence of agent instructions. This could have significant operational impacts, including unauthorized modifications to agent instructions and potential data [truncated]
CVE-2026-55541 is a high-severity vulnerability in PraisonAI, a multi-agent teams system. The issue, fixed in version 4.6.58, allows unauthenticated callers to reach certain endpoints due to a missing credential check. This vulnerability affects PraisonAI deployments, particularly those with serve agents and unified API endpoints exposed. Defenders should assess exposure, verify authentication and credent [truncated]
CVE-2026-55540 is a vulnerability in PraisonAI, a multi-agent teams system, where the is_path_within_directory() function uses os.path.abspath() instead of os.path.realpath() for workspace boundary checks. This allows a symlink within the workspace to point outside and pass the check, enabling read_file and other tools to access files outside the configured workspace. The issue is fixed in version 4.6.58.
CVE-2026-55538 is a high-severity vulnerability in PraisonAI, a multi-agent teams system. The issue arises from the improper authentication of POST requests to /agents and /agents/{agent_name} in versions prior to 4.6.58. This allows unauthenticated access to agent execution, potentially leading to unauthorized actions. The vulnerability is addressed in version 4.6.58.