#PraisonAI
All CosmicBytez Labs articles tagged #PraisonAI, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-57123: PraisonAI MCP Server Exposes Unauthenticated Tool Access
PraisonAI's MCP tools server binds to 0.0.0.0 with no auth or origin checks, letting any reachable client invoke shell and file tools.
- Security
CVE-2026-57125: PraisonAI Jobs API Lets Attackers Bypass Command-Execution Approval
Unauthenticated PraisonAI Jobs API lets a forged YAML approve field bypass @require_approval, enabling unauthenticated command execution.
- Security
CVE-2026-60090: PraisonAI SQL Injection via Unvalidated Dimension Parameter in Vector Store Backends
A CVSS 9.8 critical SQL injection vulnerability in PraisonAI before 4.6.78 allows attackers to exploit the unvalidated dimension argument in PGVector and...
- Security
CVE-2026-61445: PraisonAI AICoder Arbitrary File Write and Command Injection via LLM Tool Calls
A CVSS 9.9 critical vulnerability in PraisonAI before 4.6.78 allows attackers to write files to arbitrary filesystem locations and execute arbitrary OS...
- Security
CVE-2026-61447: PraisonAI CodeAgent Remote Code Execution via Unsandboxed Python Execution
A CVSS 10.0 critical vulnerability in PraisonAI before 1.6.78 allows attackers to achieve remote code execution by injecting malicious prompts that...
- News
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours
Threat actors began exploiting CVE-2026-44338, a missing authentication flaw in the PraisonAI multi-agent orchestration framework, within just four hours...
- Security
CVE-2026-39888: PraisonAI Sandbox Escape Enables Remote
A critical sandbox escape vulnerability in PraisonAI's multi-agent framework allows attackers to bypass the Python code execution sandbox, defeating the...
- Security
CVE-2026-39890: PraisonAI YAML Injection Achieves Remote
A critical code injection vulnerability in PraisonAI's AgentService allows attackers to craft malicious YAML files using dangerous js-yaml tags such as...