VDB
KO

package

PyPI / praisonai

pkg:pypi/praisonai

HIGH 7.3 PyPI
GHSA-6rmh-7xcm-cpxj · CVE-2026-44338

PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution

Modified: 5/11/2026

HIGH 8.1 PyPI
GHSA-78r8-wwqv-r299 · CVE-2026-47398

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

Modified: 5/29/2026

CRITICAL 9.8 PyPI
GHSA-86qc-r5v2-v6x6 · CVE-2026-47396

PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset

Modified: 5/29/2026

HIGH 8.4 PyPI
GHSA-fvxx-ggmx-3cjg · CVE-2026-40113

PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars

Modified: 4/10/2026

HIGH 8.8 PyPI
GHSA-qwgj-rrpj-75xm

PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution

Modified: 4/10/2026

HIGH 8.1 PyPI
GHSA-rg3h-x3jw-7jm5 · CVE-2026-41496

PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)

Modified: 5/12/2026