| CVE-2026-47397 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI has an Arbitrary File Write in Python API |
| CVE-2026-47391 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution |
| CVE-2026-47394 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate |
| CVE-2026-47392 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) |
| CVE-2026-47395 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context |
| CVE-2026-47393 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default |
| CVE-2026-47396 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset |
| CVE-2026-47390 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings |
| CVE-2026-47398 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334 |