CVE Tools

Praisonaiagents

48 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Praisonaiagents, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Praisonaiagents CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Praisonaiagents CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-0420
2026-053
2026-0611
2026-072
2026-085
2026-097

Severity

How the 48 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical723%
  • High1550%
  • Medium827%

Latest CVEs

The 15 most recently published vulnerabilities affecting Praisonaiagents.

  1. CVE-2026-57112PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools8.3
  2. CVE-2026-57129PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal7.5
  3. CVE-2026-57120PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder6.5
  4. CVE-2026-57123PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in9.8
  5. CVE-2026-57130PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters8.1
  6. CVE-2026-57115PraisonAI: SpiderTools redirect-target SSRF protection bypass6.5
  7. CVE-2026-57125PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass9.8
  8. CVE-2026-55530PraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool6.1
  9. CVE-2026-55526PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)8.5
  10. CVE-2026-55528praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862)8.2
  11. CVE-2026-55525PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl7.5
  12. CVE-2026-55522PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code7.8
  13. CVE-2026-47395PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context5.5
  14. CVE-2026-47390PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings5.5
  15. GHSA-4pcv-mg8v-vrgfPraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store