Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
841386
AlmaLinux
5580
Alpaquita
13555
Alpine
4441
Android
3403
Azure Linux
12016
BellSoft Hardened Containers
620
Bitnami
8907
Chainguard
10050
CleanStart
1987
CRAN
14
crates.io
2642
Debian
63564
Echo
7906
GHC
3
GIT
99617
GitHub Actions
55
Go
8744
Hackage
32
Hex
230
Julia
1672
Linux
27479
Mageia
6105
Maven
6850
MinimOS
121826
npm
226444
NuGet
1844
opam
25
openEuler
8075
openSUSE
13914
OSS-Fuzz
3980
Packagist
6833
Pub
11
PyPI
24466
Red Hat
22163
Rocky Linux
3941
Root
18939
RubyGems
4592
SUSE
22335
SwiftURL
59
TuxCare
8366
Ubuntu
60932
VSCode
20
Wolfi
7149
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3524
PyPI/praisonai-platform
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
23 Jul
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3504
PyPI/praisonai
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
23 Jul
Fix available
Severity - 8.8 (High)
PYSEC-2026-3508
PyPI/praisonai
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
23 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-3525
PyPI/praisonai-platform
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
23 Jul
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3500
PyPI/praisonai
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
23 Jul
Fix available
Severity - 9.1 (Critical)
PYSEC-2026-3515
PyPI/praisonai
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
23 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-3505
PyPI/praisonai
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
23 Jul
Fix available
Severity - 7.8 (High)
PYSEC-2026-3509
PyPI/praisonai
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
23 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-3512
PyPI/praisonai
PraisonAI Code agent tools fail open without a workspace boundary
23 Jul
Fix available
Severity - 7.3 (High)
PYSEC-2026-3517
PyPI/praisonai
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
23 Jul
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3523
PyPI/praisonai
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
23 Jul
Fix available
Severity - 8.6 (High)
PYSEC-2026-3526
PyPI/praisonai-platform
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
23 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-3507
PyPI/praisonai
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
23 Jul
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3519
PyPI/praisonai
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
23 Jul
Fix available
Severity - 7.2 (High)
PYSEC-2026-3511
PyPI/praisonai
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
23 Jul
Fix available
Severity - 9.8 (Critical)
PYSEC-2026-3513
PyPI/praisonai
praisonai: recipe serve auth middleware silently disables itself when no secret is set
23 Jul
Fix available
Severity - 9.8 (Critical)
Load more...
PyPI - OSV