Technology · PyPI
praisonai-platform (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in praisonai-platform (PyPI): 0 in the last 7 days and 19 in the last 90 days, 8 of them critical and 0 exploited in the wild. The most recent, CVE-2026-57148, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 19
- Critical, all time
- 8
- Exploited in the wild
- 0
About praisonai-platform (PyPI)
PraisonAI is an artificial intelligence framework designed to orchestrate multi-agent systems.
Latest praisonai-platform (PyPI) vulnerabilities
- CVE-2026-57148: PraisonAI JWT authentication bypass with hardcoded dev secretcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-57147: PraisonAI JWT authentication bypass with hardcoded secretcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-57121: PYSEC-2026-3526 - PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in…lowCVSS 3.1
- CVE-2026-47419: MervinPraison PraisonAI Platform IDOR in agent CRUD endpointshighCVSS 8.3EPSS 0.4%
- CVE-2026-47418: MervinPraison PraisonAI Platform IDOR in project endpointshighCVSS 8.1EPSS 0.4%
- CVE-2026-47417: MervinPraison PraisonAI Platform IDOR in comment endpointshighCVSS 8.1EPSS 0.4%
- CVE-2026-47416: MervinPraison PraisonAI Platform privilege escalation in workspace members endpointcriticalCVSS 9.6EPSS 0.4%
- CVE-2026-47415: MervinPraison PraisonAI Platform IDOR in issue endpointshighCVSS 8.3EPSS 0.4%
- CVE-2026-47414: MervinPraison PraisonAI Platform IDOR in label endpointshighCVSS 7.6EPSS 0.4%
- CVE-2026-47413: MervinPraison PraisonAI Platform privilege escalation in workspace members endpointcriticalCVSS 9.6EPSS 0.4%
- CVE-2026-47412: MervinPraison PraisonAI Platform authorization bypass in workspace deletionhighCVSS 8.1EPSS 0.5%
- CVE-2026-47411: MervinPraison PraisonAI Platform authorization bypass in workspace settingsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-47410: MervinPraison PraisonAI Platform hardcoded JWT secretcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-47409: MervinPraison PraisonAI Platform authorization bypass in member removalhighCVSS 8.1EPSS 0.5%
- CVE-2026-47408: MervinPraison PraisonAI Platform IDOR in issue activity endpointmediumCVSS 6.5EPSS 0.4%
- CVE-2026-47407: MervinPraison PraisonAI Platform IDOR and privilege escalationcriticalCVSS 4EPSS 0.4%
- CVE-2026-47406: MervinPraison PraisonAI Platform IDOR in dependency endpointshighCVSS 8.1EPSS 0.4%
- CVE-2026-47405: MervinPraison PraisonAI Platform privilege escalation in workspace managementhighCVSS 8.8EPSS 0.5%
- CVE-2026-47399: MervinPraison PraisonAI Platform IDOR in workspace-scoped routeshighCVSS 8.8EPSS 0.5%
- MervinPraison praisonai-platform authorization bypass in issue endpointsmediumCVSS 4.3
- MervinPraison praisonai-platform JWT secret forgery in auth_servicecriticalCVSS 9.8
- MervinPraison praisonai-platform authentication bypass via hardcoded JWT secretcriticalCVSS 9.8
- PraisonAI Platform improper authorization in DELETE endpointshighCVSS 8.1
- CVE-2026-48169: PraisonAI Platform IDOR and privilege escalation in Platform APIhighCVSS 8.8EPSS 0.4%
Most severe praisonai-platform (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-57147: PraisonAI JWT authentication bypass with hardcoded secretcriticalCVSS 9.8EPSS 0.8%
- CVE-2026-57148: PraisonAI JWT authentication bypass with hardcoded dev secretcriticalCVSS 9.8EPSS 0.6%
- CVE-2026-47410: MervinPraison PraisonAI Platform hardcoded JWT secretcriticalCVSS 9.8EPSS 0.6%
- MervinPraison praisonai-platform JWT secret forgery in auth_servicecriticalCVSS 9.8
- MervinPraison praisonai-platform authentication bypass via hardcoded JWT secretcriticalCVSS 9.8
- CVE-2026-47416: MervinPraison PraisonAI Platform privilege escalation in workspace members endpointcriticalCVSS 9.6EPSS 0.4%
- CVE-2026-47413: MervinPraison PraisonAI Platform privilege escalation in workspace members endpointcriticalCVSS 9.6EPSS 0.4%
- CVE-2026-47407: MervinPraison PraisonAI Platform IDOR and privilege escalationcriticalCVSS 4EPSS 0.4%
- CVE-2026-47405: MervinPraison PraisonAI Platform privilege escalation in workspace managementhighCVSS 8.8EPSS 0.5%
- CVE-2026-47399: MervinPraison PraisonAI Platform IDOR in workspace-scoped routeshighCVSS 8.8EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 17 | 4 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 2 | 2 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/praisonai-platform.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "praisonai-platform (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/praisonai-platform, 26 September 2026.