CVE Tools

Praison

157 CVEs tracked since 2026. Since Apr 2026, none of them reached CISA KEV.

Praison CVEs per month

Apr 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Praison CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-04440
2026-0590
2026-06null or fewer
2026-07540
2026-08220
2026-09280

Products

The products that kept showing up in Praison's monthly top three, with their CVEs summed over those months.

  1. Praisonai1305 months
  2. Praisonaiagents305 months
  3. Praisonai-platform193 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Praison.

  1. CVE-2026-44340PraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`7.5
  2. CVE-2026-44339PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute8.6
  3. CVE-2026-44338PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution7.3
  4. CVE-2026-44337PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries6.3
  5. CVE-2026-44336PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection9.6
  6. CVE-2026-44335SSRF bypass in PraisonAI9.8
  7. CVE-2026-44334PraisonAI: Unauthenticated RCE via `tool_override.py`8.4
  8. CVE-2026-41497Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI9.8
  9. CVE-2026-41496PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)8.1
  10. CVE-2026-40313PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence9.1
  11. CVE-2026-40289PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions9.1
  12. CVE-2026-40288PraisonAI: Critical RCE via `type: job` workflow YAML9.8
  13. CVE-2026-40287PraisonAI has RCE via Automatic tools.py Import8.4
  14. CVE-2026-40315PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries9.8
  15. CVE-2026-40160PraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallback6.5

The record

Peak rank
#15 in Jul 2026
Busiest month shown
Jul 2026, 54 CVEs
Months with a KEV entry
0 since Apr 2026
Monthly snapshots
5 since 2026
Praison's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store