PatchSiren

MervinPraison CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH MervinPraison CVE published 2026-08-25

CVE-2026-55537

CVE-2026-55537 is a HIGH severity vulnerability in PraisonAI, a multi-agent teams system, with a CVSS score of 7.1. The vulnerability exists in the JobSubmitRequest.validate_webhook_url() method, which accepts webhook URLs even when DNS resolution raises a socket.gaierror exception. This allows an attacker to potentially direct requests to an internal service. The issue is fixed in version 4.6.58.

MEDIUM MervinPraison CVE published 2026-08-25

CVE-2026-55535

CVE-2026-55535 is a vulnerability in PraisonAI's multi-agent teams system, specifically in the Jobs API's validate_webhook_url() path. The issue allows an attacker to bypass validation and potentially access internal addresses. This vulnerability has been fixed in version 4.6.58. Defenders should assess exposure and prioritize updates to version 4.6.58 or later. The CVE record and NVD entry provide detail [truncated]

HIGH MervinPraison CVE published 2026-08-25

CVE-2026-55534

CVE-2026-55534 is a high-severity vulnerability in PraisonAI, a multi-agent teams system. The issue allows unauthenticated network callers to invoke configured agents without credentials when an API key is supplied. This vulnerability was fixed in version 4.6.58. Affected deployments should prioritize verification and updating to prevent exploitation. Network administrators and security teams should revie [truncated]

MEDIUM MervinPraison CVE published 2026-08-25

CVE-2026-55531

CVE-2026-55531 is a vulnerability in PraisonAI, a multi-agent teams system, that can lead to memory exhaustion. The MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize request without proper cleanup or session limits, allowing an unauthenticated attacker to consume memory. The issue is fixed in version 4.6.58, which invokes cleanup and limits sessions through PRAISONAI_MCP_ [truncated]

MEDIUM MervinPraison CVE published 2026-08-25

CVE-2026-55530

CVE-2026-55530 is a medium-severity vulnerability in the PraisonAI multi-agent teams system. The issue, fixed in version 1.6.58, involves the ast_grep_rewrite function lacking the @require_approval decorator, allowing unauthorized file rewriting. This CVE was published on 2026-08-25T15:16:33.870Z and was last modified on 2026-09-09T21:07:31.353Z. Defenders should assess exposure and verify the 1.6.58 upda [truncated]

MEDIUM MervinPraison CVE published 2026-08-25

CVE-2026-55529

CVE-2026-55529 is a vulnerability in PraisonAI, a multi-agent teams system, that allows an attacker to execute exposed tools without an API key by exploiting the MCP HTTP Stream _validate_origin method. This issue is fixed in version 4.6.58. The vulnerability enables a malicious webpage to submit tools/call requests to the local MCP server and execute exposed tools. Defenders should assess exposure and pr [truncated]

HIGH MervinPraison CVE published 2026-08-25

CVE-2026-55528

CVE-2026-55528 is a high-severity vulnerability in PraisonAI's multi-agent teams system. The issue arises from the AgentServer exposing the ServerConfig.auth_token without proper validation in the AgentServer._create_app method. This allows remote callers to perform actions without a valid bearer token or X-Auth-Token even when authentication is configured. The vulnerability is fixed in version 1.6.58.

HIGH MervinPraison CVE published 2026-08-25

CVE-2026-55527

A vulnerability in PraisonAI's multi-agent teams system, specifically in the FileMemory constructor, allows an attacker to write JSON data to arbitrary process-writable locations by supplying unsanitized user_id input. This issue, fixed in version 1.6.58, has a CVSS score of 7.1 and is considered HIGH severity. The vulnerability arises from the constructor joining unsanitized user_id into self.user_path, [truncated]

HIGH MervinPraison CVE published 2026-08-25

CVE-2026-55526

CVE-2026-55526 is a vulnerability in PraisonAI's multi-agent teams system, specifically in the spider_tools._host_is_blocked() function. The issue allows for internal HTTP access due to improper hostname validation. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP access. The fix uses socket.getaddrinfo and fails closed on DNS errors. This vulnerabil [truncated]

HIGH MervinPraison CVE published 2026-08-25

CVE-2026-55525

CVE-2026-55525 is a vulnerability in the PraisonAI multi-agent teams system, specifically in the web_crawl function of praisonaiagents versions prior to 1.6.58. The issue allows an attacker to redirect a public URL to loopback, private network, or cloud metadata services, potentially leading to unauthorized access to internal responses. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity.

HIGH MervinPraison CVE published 2026-08-07

CVE-2026-48169

CVE-2026-48169 is a high-severity vulnerability in the PraisonAI Platform API, with a CVSS score of 8.8. The vulnerability allows any authenticated user to read, modify, and delete resources in any workspace by swapping UUIDs in their API requests. Additionally, any workspace member can promote themselves to owner and kick out the original owner. The issue is patched in version 0.1.4 of the PraisonAI Platform API.

HIGH MervinPraison CVE published 2026-08-05

CVE-2026-55524

PraisonAI's web_crawl tool in versions prior to 1.6.58 is vulnerable to SSRF attacks due to a validate-here/fetch-there gap. The tool performs SSRF checks only on the initially supplied URL and does not revalidate the hostname when following redirects or during DNS rebinding. This allows attackers to bypass protections and connect to internal destinations, potentially fetching data from loopback, private- [truncated]

HIGH MervinPraison CVE published 2026-08-05

CVE-2026-55522

CVE-2026-55522 is a high-severity vulnerability in PraisonAI, a multi-agent teams system, affecting versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents. The vulnerability allows for arbitrary Python code execution via the workflow 'include' feature. An attacker can exploit this by causing a victim process to run a workflow or recipe that includes an untrusted local [truncated]

CRITICAL MervinPraison CVE published 2026-08-05

CVE-2026-48168

CVE-2026-48168 is a critical vulnerability in PraisonAI, a multi-agent teams system, due to a command injection weakness in its bundled Claude GitHub Actions workflow. This issue allows an outside contributor to execute arbitrary shell code by opening a pull request with a malicious branch name and commenting @claude, potentially leading to repository writes, pull request manipulation, or OIDC-token abuse [truncated]

HIGH MervinPraison CVE published 2026-07-21

CVE-2026-47419

CVE-2026-47419 is an Insecure Direct Object Reference vulnerability in PraisonAI Platform versions prior to 0.1.4. The agent CRUD endpoints gate access on workspace membership only, then resolve agent IDs through a primary-key lookup with no workspace constraint. This allows users who are members of any workspace to read, modify, or delete agents from a different workspace by guessing or harvesting an age [truncated]

HIGH MervinPraison CVE published 2026-07-21

CVE-2026-47418

CVE-2026-47418 is an Insecure Direct Object Reference vulnerability in PraisonAI Platform versions prior to 0.1.4. The project CRUD endpoints gate access on workspace membership only, then resolve project IDs without constraining lookups by workspace ID. This allows a user who is a member of any workspace W1 to read, modify, delete, or read stats for projects that belong to a different workspace W2. The v [truncated]

CRITICAL MervinPraison CVE published 2026-07-21

CVE-2026-47416

CVE-2026-47416 is a critical vulnerability in PraisonAI Platform versions prior to 0.1.4. The vulnerability allows for vertical privilege escalation via the PATCH /workspaces/{workspace_id}/members/{user_id} endpoint. This endpoint is gated by require_workspace_member(workspace_id), which defaults to min_role='member' and is never overridden by the route. The handler then calls MemberService.update_role(w [truncated]

CRITICAL MervinPraison CVE published 2026-07-21

CVE-2026-47413

CVE-2026-47413 is a critical vulnerability in PraisonAI Platform versions prior to 0.1.4, allowing for privilege escalation and cross-tenant member injection. The vulnerability exists in the `POST /workspaces/{workspace_id}/members` endpoint, which is gated only by `require_workspace_member(workspace_id)` and forwards the request body's `user_id` and `role` straight into `MemberService.add(workspace_id, u [truncated]

HIGH MervinPraison CVE published 2026-07-21

CVE-2026-47412

CVE-2026-47412 is an authorization bypass vulnerability in PraisonAI Platform versions prior to 0.1.4. The DELETE /workspaces/{workspace_id} endpoint is gated only by require_workspace_member(workspace_id) (default min_role='member'). Any member of the workspace can issue a single DELETE to wipe the entire workspace, including every project, issue, comment, agent, label, and member record (cascading via f [truncated]

CRITICAL MervinPraison CVE published 2026-07-21

CVE-2026-47410

CVE-2026-47410 is a critical vulnerability in PraisonAI Platform versions prior to 0.1.4. The platform's JWT signing secret defaults to a hardcoded literal 'dev-secret-change-me' when PLATFORM_JWT_SECRET is unset. A safety check exists but only fires when PLATFORM_ENV != 'dev'; the default value of PLATFORM_ENV is 'dev', so the check is silently bypassed in any deployment that does not explicitly opt out. [truncated]

CRITICAL MervinPraison CVE published 2026-07-21

CVE-2026-47407

CVE-2026-47407 is a critical vulnerability in PraisonAI Platform version prior to 0.1.4. The Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_member(workspace_id)` FastAPI dependency. However, this dependency only checks if the caller is a member of the workspace_id in the URL prefix, not the resource's own workspace_id. This allow [truncated]

HIGH MervinPraison CVE published 2026-07-21

CVE-2026-47399

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T17:17:08.950Z and has not been modified since then. PraisonAI Platform versions prior to 0.1.4 contain a systemic object-level authorization flaw in workspace-scoped REST routes. This flaw allows an authenticated user from one workspace to access, modify, or delete objects from another workspace [truncated]

CRITICAL MervinPraison CVE published 2026-07-21

CVE-2026-47396

CVE-2026-47396 is a critical vulnerability in PraisonAI's call server, affecting the `praisonai.api.agent_invoke` component. The vulnerability allows unauthorized access to sensitive agent-control endpoints when `CALL_SERVER_TOKEN` is not configured. This issue is particularly concerning as the bundled call server binds to `0.0.0.0`, making it accessible to any client on the network. The vulnerability has [truncated]

CRITICAL MervinPraison CVE published 2026-07-21

CVE-2026-47393

CVE-2026-47393 is a critical vulnerability in PraisonAI, a multi-agent teams system. The issue arises from a code-generator that creates a Flask API server with authentication disabled by default. This affects users who follow the quickstart guide and deploy the API server binding to 0.0.0.0, exposing endpoints like /chat and /agents. The server runs praisonai.run() on user-supplied JSON input, which incl [truncated]

MEDIUM MervinPraison CVE published 2026-07-21

CVE-2026-47390

CVE-2026-47390 is a server-side request forgery (SSRF) protection bypass vulnerability in PraisonAI, a multi-agent teams system. The vulnerability exists in the `spider_tools` URL validation function, which can be bypassed using alternate loopback host encodings. This allows an attacker to induce SSRF requests against loopback-only services. The vulnerability was patched in PraisonAI version 4.6.40 and pr [truncated]

HIGH MervinPraison CVE published 2026-04-04

CVE-2026-34955

A vulnerability was discovered in PraisonAI's SubprocessSandbox feature, which allows for trivial sandbox escape in STRICT mode. The issue arises from the use of subprocess.run() with shell=True and inadequate string-pattern matching to block dangerous commands. Specifically, the blocklist does not include sh or bash as standalone executables, permitting an attacker to execute arbitrary commands using sh [truncated]

HIGH MervinPraison CVE published 2026-04-03

CVE-2026-34954

CVE-2026-34954 is a vulnerability in the PraisonAI multi-agent teams system, specifically in the FileTools.download_file() function. Prior to version 1.5.95, this function validates the destination path but does not validate the URL parameter, passing it directly to httpx.stream() with follow_redirects=True. This allows an attacker who controls the URL to reach any host accessible from the server, includi [truncated]

CRITICAL MervinPraison CVE published 2026-04-03

CVE-2026-34953

CVE-2026-34953 is a critical vulnerability in PraisonAI's OAuthManager.validate_token() function. Prior to version 4.5.97, the function returns True for any token not found in its internal store, which is empty by default. This allows any HTTP request to the MCP server with an arbitrary Bearer token to be treated as authenticated, granting full access to all registered tools and agent capabilities. The is [truncated]

CRITICAL MervinPraison CVE published 2026-04-03

CVE-2026-34952

CVE-2026-34952 is a critical vulnerability in PraisonAI, a multi-agent teams system. The PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info without authentication. This allows any network client to connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. The issue has been patched in version 4.5.97. Users and administrat [truncated]

MEDIUM MervinPraison CVE published 2026-04-03

CVE-2026-34939

A vulnerability in PraisonAI's MCPToolIndex.search_tools() function allows for catastrophic backtracking, leading to a service outage. The issue was patched in version 4.5.90. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The CVE record was published on 2026-04-03T23:17:06.330Z and was last modified on 2026-07-24T22:10:00.140Z.