praisonai Security Analysis
praisonai has 42 known security vulnerabilities in PyPI (Python). Upgrade to version 4.6.61 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 4.6.61
Upgrading to 4.6.61 or later resolves all 42 known vulnerabilities in praisonai. Run: pip install "praisonai>=4.6.61"
Is praisonai in your project?
Check if you're affected and upgrade to 4.6.61 to stay secure.
Vulnerabilities
42 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-40288 PraisonAI has critical RCE via `type: job` workflow YAML | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+691 more) | 4.5.139 |
| CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-57124 PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-57116 PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation | CRITICAL | 4.2.1, 4.2.2, 4.2.3, 4.2.4 (+192 more) | 4.6.59 |
| CVE-2026-57131 PraisonAI: Jobs API exposes agent-execution endpoints with no authentication | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-57125 PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-41497 PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+696 more) | 4.5.149 |
| CVE-2026-39890 PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+669 more) | 4.5.115 |
| CVE-2026-34935 PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command() | CRITICAL | 4.5.15, 4.5.16, 4.5.18, 4.5.19 (+44 more) | 4.5.69 |
| CVE-2026-34934 PraisonAI Has Second-Order SQL Injection in `get_all_user_threads` | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+647 more) | 4.5.90 |
| CVE-2026-40288 PraisonAI has critical RCE via `type: job` workflow YAML | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+691 more) | 4.5.139 |
| CVE-2026-57124 PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-57116 PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation | CRITICAL | 4.2.1, 4.2.2, 4.2.3, 4.2.4 (+192 more) | 4.6.59 |
| CVE-2026-57131 PraisonAI: Jobs API exposes agent-execution endpoints with no authentication | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-57127 praisonai: recipe serve auth middleware silently disables itself when no secret is set | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+745 more) | 4.6.59 |
| CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+727 more) | 4.6.40 |
| CVE-2026-41497 PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+696 more) | 4.5.149 |
| CVE-2026-39890 PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+669 more) | 4.5.115 |
| CVE-2026-34934 PraisonAI Has Second-Order SQL Injection in `get_all_user_threads` | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+647 more) | 4.5.90 |
| CVE-2026-34935 PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command() | CRITICAL | 4.5.15, 4.5.16, 4.5.18, 4.5.19 (+44 more) | 4.5.69 |
| CVE-2026-44336 PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+721 more) | 4.6.34 |
| CVE-2026-40088 PraisonAI Vulnerable to OS Command Injection | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+674 more) | 4.5.121 |
| CVE-2026-40157 PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack` | CRITICAL | 2.8.3, 2.8.4, 2.8.5, 2.8.6 (+292 more) | 4.5.128 |
| CVE-2026-44336 PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+721 more) | 4.6.34 |
| CVE-2026-40157 PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack` | CRITICAL | 2.8.3, 2.8.4, 2.8.5, 2.8.6 (+292 more) | 4.5.128 |
| CVE-2026-40088 PraisonAI Vulnerable to OS Command Injection | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+674 more) | 4.5.121 |
| CVE-2026-40154 PraisonAI Vulnerable Untrusted Remote Template Code Execution | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+681 more) | 4.5.128 |
| CVE-2026-40289 PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+691 more) | 4.5.139 |
| CVE-2026-40154 PraisonAI Vulnerable Untrusted Remote Template Code Execution | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+681 more) | 4.5.128 |
| CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+747 more) | 4.6.61 |
| CVE-2026-34952 PraisonAI Has Missing Authentication in WebSocket Gateway | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+652 more) | 4.5.97 |
| CVE-2026-34953 PraisonAI Has Authentication Bypass via OAuthManager.validate_token() | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+652 more) | 4.5.97 |
| CVE-2026-40289 PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+691 more) | 4.5.139 |
| CVE-2026-57145 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation | CRITICAL | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+747 more) | 4.6.61 |
About This Data
Vulnerability data for praisonai is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related PyPI (Python) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of praisonai.