PraisonAI: Webhook signature verification skipped (fail-open) when secret unset

CVSS 8.6 praisonai View details

MCP Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url

CVSS 8.2 mcp-atlassian View details

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery

CVSS 6.5 agentos-taskweaver View details

OpenClaw: Lower-trust background runtime output is injected into trusted

npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation

CVSS 9.4 praisonai View details

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch

CVSS 7.4 deepseek-tui View details
CVE MEDIUM CVE-2026-40151

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in

CVSS 5.3 PraisonAI View details
CVE UNKNOWN CVE-2024-48919

Cursor is a code editor built for programming with AI

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web

CVSS 7.1 mcp-searxng View details

npm PraisonAI SandboxExecutor network-isolated mode does not block non

CVSS 7.6 praisonai View details

PraisonAI: Compute-bridged file tools allow shell command injection

CVSS 8.8 praisonai View details

Pi Agent: Potential XSS in HTML session exports via Markdown

CVSS 2.5 @earendil-works/pi-coding-agent View details

PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show

PraisonAI View details
CVE CRITICAL CVE-2026-47392

PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak

CVSS 9.9 PraisonAI View details

PraisonAI ships and generates a legacy API server with authentication

CVSS 7.3 PraisonAI View details
CVE MEDIUM CVE-2026-43901

wireshark-mcp vulnerable to arbitrary file write via export_objects

CVSS 6.8 wireshark-mcp View details

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated

CVSS 8.6 pptagent View details

OpenClaw's gateway config mutation guard allowed unsafe model-driven

CVSS 8.8 openclaw View details

OpenClaw: Webchat audio embedding could read local files without local

OpenClaw: Agent gateway config mutations could change protected operator settings

Previous Page 4 of 6 Next