Vulnerabilities in MervinPraison

158 results
Vexday analysis

O portfólio de vulnerabilidades da MervinPraison apresenta um perfil atípico: todas as 53 CVEs catalogadas surgiram nos últimos 90 dias, indicando um produto recente ou uma fila de divulgação concentrada, e nenhuma delas consta no catálogo CISA KEV, taxa abaixo da média geral. Ainda assim, 18 falhas são classificadas como críticas e a falha mais predominante é CWE-22 (Path Traversal), tipo de vulnerabilidade com potencial significativo de impacto em confidencialidade e integridade de dados. A CVE mais perigosa atualmente, CVE-2026-44338, registra EPSS de 0,268, sugerindo probabilidade não negligenciável de exploração em breve, especialmente considerando a existência de ao menos um PoC público no conjunto. Equipes de segurança devem priorizar a remediação das falhas críticas e monitorar de perto a evolução do EPSS de CVE-2026-44338 diante da ausência de exploração confirmada, mas contexto de exposição crescente.

CVE-2026-40156HIGHPraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` LoadingEPSS 0.2%CVE-2026-55526HIGHPraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)EPSS 0.2%CVE-2026-55524HIGHPraisonAI: SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)EPSS 0.2%CVE-2026-57112HIGHPraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered toolsEPSS 0.2%CVE-2026-47395MEDIUMPraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model contextEPSS 0.2%CVE-2026-40159MEDIUMPraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess ExecutionEPSS 0.2%CVE-2026-60088MEDIUMPraisonAI before 4.6.78 Path Traversal via Custom CommandsEPSS 0.2%CVE-2026-60089MEDIUMPraisonAI before 1.6.78 Path Traversal via config.tomlEPSS 0.2%CVE-2026-55537HIGHPraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114EPSS 0.2%CVE-2026-47390MEDIUMPraisonAI spider_tools SSRF protection bypass via alternate loopback host encodingsEPSS 0.2%CVE-2026-61437HIGHPraisonAI before 1.6.78 Remote Code Execution via tools.pyEPSS 0.2%CVE-2026-57128MEDIUMPraisonAI: Unauthenticated Event Injection via SSE `/publish` EndpointEPSS 0.2%CVE-2026-55522HIGHPraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe codeEPSS 0.2%CVE-2026-60087MEDIUMPraisonAI before 1.6.78 Tool Approval Cache BypassEPSS 0.1%CVE-2026-57122HIGHPraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)EPSS 0.1%CVE-2026-55532HIGHPraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP serverEPSS 0.1%CVE-2026-55529MEDIUMPraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP serverEPSS 0.1%CVE-2026-55530MEDIUMPraisonAI: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation toolEPSS 0.1%