Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3886
  • PyPI/praisonai
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) 10 Sep
  • Fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-3892
  • PyPI/praisonai
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server 10 Sep
  • Fix available
  • Severity - 7.6 (High)
PYSEC-2026-3889
  • PyPI/praisonai
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret 10 Sep
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-3885
  • PyPI/praisonai
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete 10 Sep
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-3893
  • PyPI/praisonai
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced 10 Sep
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3890
  • PyPI/praisonai
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation 10 Sep
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-3895
  • PyPI/praisonai
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114 10 Sep
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3894
  • PyPI/praisonai
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated 10 Sep
  • Fix available
  • Severity - 7.3 (High)
PYSEC-2026-3888
  • PyPI/praisonai
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks 10 Sep
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3887
  • PyPI/praisonai
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution 10 Sep
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-3897
  • PyPI/praisonai
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced) 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-3896
  • PyPI/praisonai
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server 10 Sep
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-3891
  • PyPI/praisonai
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code 10 Sep
  • Fix available
  • Severity - 7.8 (High)
GHSA-6g6r-q6gw-w8fg
  • PyPI/praisonai
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) 25 Aug
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-pvph-5j39-v8qc
  • PyPI/praisonai
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server 25 Aug
  • Fix available
  • Severity - 7.6 (High)
GHSA-gfq8-hmph-9gjv
  • PyPI/praisonai
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret 25 Aug
  • Fix available
  • Severity - 8.2 (High)