PraisonAI Vulnerabilities

pip AI Agents

AI Threat Alert tracks 142 known vulnerabilities in PraisonAI, 37 rated critical — an AI/ML ai agents in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
142
Total CVEs
37
Critical
pip
Ecosystem
Aug 5, 2026
Last CVE
66%
Patch Rate
14d
Avg Time to Patch

Known Vulnerabilities (142 total, page 1 of 6)

Severity CVE ID Summary CVSS Published
HIGH CVE-2026-55524 PraisonAI: SSRF bypass in web_crawl via TOCTOU/rebinding 7.5 Aug 5, 2026 HIGH CVE-2026-55522 PraisonAI: RCE via workflow include bypasses safe loader 7.8 Aug 5, 2026 CRITICAL CVE-2026-48168 PraisonAI: shell injection in Claude Action enables RCE 10.0 Aug 5, 2026 HIGH CVE-2026-61436 PraisonAI: missing webhook signature check spoofs agents 8.6 Jul 15, 2026 HIGH CVE-2026-61446 PraisonAI: RCE via unsigned plugin auto-load 8.4 Jul 15, 2026 HIGH CVE-2026-61443 PraisonAI: path traversal leads to RCE via SkillTools 8.1 Jul 15, 2026 MEDIUM CVE-2026-61440 PraisonAI: broken authz lets members hijack labels 6.5 Jul 15, 2026 HIGH CVE-2026-61438 PraisonAI: RCE via broken AST sandbox in workflows 7.3 Jul 15, 2026 HIGH CVE-2026-61433 PraisonAI: code injection via unsafe config codegen 7.8 Jul 15, 2026 HIGH CVE-2026-60085 PraisonAI: sandbox policy no-op enables RCE, file read 7.5 Jul 15, 2026 MEDIUM CVE-2026-60087 PraisonAI: approval caching flaw enables file write abuse 6.1 Jul 15, 2026 HIGH CVE-2026-61430 PraisonAI: DNS rebinding SSRF bypass in web_crawl 8.5 Jul 15, 2026 HIGH CVE-2026-61435 PraisonAI: Host header spoof bypasses agent auth 8.2 Jul 15, 2026 HIGH CVE-2026-61427 PraisonAI: MCP server auth bypass by default 7.3 Jul 15, 2026 CRITICAL CVE-2026-61447 PraisonAI: RCE via unsandboxed LLM code execution 10.0 Jul 11, 2026 CRITICAL CVE-2026-61445 PraisonAI: AICoder root RCE via unsanitized tool calls 9.9 Jul 11, 2026 HIGH CVE-2026-61439 PraisonAI: umbral de bloqueo mal configurado permite prompt injection 7.5 Jul 11, 2026 HIGH CVE-2026-61429 PraisonAI: SSRF bypass via DNS rebinding/redirects 8.5 Jul 11, 2026 HIGH CVE-2026-61428 PraisonAI: webhook signature bypass enables spoofing 7.3 Jul 11, 2026 HIGH CVE-2026-61426 PraisonAI: insecure defaults expose agent secrets 8.6 Jul 11, 2026 CRITICAL CVE-2026-60090 PraisonAI: SQL/CQL injection via unvalidated vector dim 9.8 Jul 11, 2026 MEDIUM CVE-2026-60088 PraisonAI: path traversal leaks files into LLM prompts 5.5 Jul 11, 2026 CRITICAL CVE-2026-61444 PraisonAI: code injection via f-string in deploy API 9.1 Jul 10, 2026 HIGH CVE-2026-61437 PraisonAI: unsafe dynamic import enables RCE 7.8 Jul 10, 2026 HIGH CVE-2026-61434 PraisonAI: allowlist bypass enables RCE via find -exec 8.8 Jul 10, 2026

Showing 1–25 of 142

Frequently asked questions

What is PraisonAI?

PraisonAI is an AI/ML ai agents tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does PraisonAI have?

PraisonAI has 142 known CVEs, 37 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is PraisonAI distributed in?

PraisonAI is distributed via the pip ecosystem and categorized as ai agents.

Where does the PraisonAI vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of PraisonAI?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor PraisonAI in your stack

Get instant alerts when new vulnerabilities affect PraisonAI. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring