Technology · PyPI
praisonai (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 86 vulnerabilities in praisonai (PyPI): 0 in the last 7 days and 49 in the last 90 days, 22 of them critical and 0 exploited in the wild. The most recent, CVE-2026-57112, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 49
- Critical, all time
- 22
- Exploited in the wild
- 0
Latest praisonai (PyPI) vulnerabilities
- CVE-2026-57112: PraisonAI legacy SSE endpoint CORS and authentication bypasshighCVSS 8.3EPSS 0.2%
- CVE-2026-57145: PraisonAI path traversal in multiedit toolcriticalCVSS 9.1EPSS 0.5%
- CVE-2026-57132: PraisonAI authentication bypass with PRAISONAI_CALL_AUTH disabledhighCVSS 8.2EPSS 0.5%
- CVE-2026-57131: PraisonAI unauthenticated API access to jobs endpointcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-57127: PraisonAI authentication bypass in recipe servecriticalCVSS 9.8EPSS 0.9%
- CVE-2026-57124: PraisonAI unauthenticated remote code execution in MCP endpointcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-57122: PraisonAI webhook authentication bypass in WhatsApp and Linear handlershighCVSS 8.6EPSS 0.2%
- CVE-2026-57119: PraisonAI Jobs API path traversalhighCVSS 7.5EPSS 0.5%
- CVE-2026-56839: PraisonAI path traversal in CODE_TOOLS helpershighCVSS 7.3EPSS 0.4%
- CVE-2026-57125: PraisonAI unauthenticated remote code execution via /api/v1/runscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-55539: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs…highCVSS 8.6EPSS 0.6%
- CVE-2026-55536: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome…criticalCVSS 9.1EPSS 0.5%
- CVE-2026-55533: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when…highCVSS 8.2EPSS 0.5%
- CVE-2026-55532: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses…highCVSS 7.6EPSS 0.2%
- CVE-2026-55541: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified…highCVSS 4EPSS 0.5%
- CVE-2026-55540: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath()…highCVSS 7.1EPSS 0.4%
- CVE-2026-55538: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but…highCVSS 7.3EPSS 0.4%
- CVE-2026-55537: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts…highCVSS 7.1EPSS 0.3%
- CVE-2026-55535: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on…mediumCVSS 6.8EPSS 0.3%
- CVE-2026-55534: PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but…highCVSS 8.6EPSS 0.4%
- CVE-2026-55531: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-55529: PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts…mediumCVSS 6.9EPSS 0.2%
- CVE-2026-55522: PraisonAI workflow include remote code execution in tools.pyhighCVSS 7.8EPSS 0.2%
- CVE-2026-57144: PYSEC-2026-3504 - PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailablelowCVSS 3.1
- CVE-2026-57146: PYSEC-2026-3515 - PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by defaultlowCVSS 3.1
Most severe praisonai (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-47392: MervinPraison PraisonAI sandbox escape in execute_code toolcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-47391: MervinPraison PraisonAI remote code execution in A2A server examplecriticalCVSS 9.8EPSS 1.2%
- CVE-2026-57124: PraisonAI unauthenticated remote code execution in MCP endpointcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-34935: MervinPraison PraisonAI OS command injection in MCPHandlercriticalCVSS 9.8EPSS 1.0%
- CVE-2026-57131: PraisonAI unauthenticated API access to jobs endpointcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-40288: MervinPraison PraisonAI RCE via job workflow YAMLcriticalCVSS 9.8EPSS 0.9%
- CVE-2026-57127: PraisonAI authentication bypass in recipe servecriticalCVSS 9.8EPSS 0.9%
- CVE-2026-39890: MervinPraison PraisonAI RCE via YAML deserialization in AgentServicecriticalCVSS 9.8EPSS 0.8%
- CVE-2026-47393: MervinPraison PraisonAI missing authentication in generated API servercriticalCVSS 9.8EPSS 0.8%
- CVE-2026-41497: PraisonAI has an incomplete fix for - OS Command InjectioncriticalCVSS 9.8EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 3 | 0 | |
| 20 Jul 2026 | 23 | 4 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 13 | 1 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 10 | 5 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-praisonai.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "praisonai (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-praisonai, 28 September 2026.