Vulnerabilidades en MervinPraison

158 resultados
Análisis Vexday

O portfólio de vulnerabilidades da MervinPraison apresenta um perfil atípico: todas as 53 CVEs catalogadas surgiram nos últimos 90 dias, indicando um produto recente ou uma fila de divulgação concentrada, e nenhuma delas consta no catálogo CISA KEV, taxa abaixo da média geral. Ainda assim, 18 falhas são classificadas como críticas e a falha mais predominante é CWE-22 (Path Traversal), tipo de vulnerabilidade com potencial significativo de impacto em confidencialidade e integridade de dados. A CVE mais perigosa atualmente, CVE-2026-44338, registra EPSS de 0,268, sugerindo probabilidade não negligenciável de exploração em breve, especialmente considerando a existência de ao menos um PoC público no conjunto. Equipes de segurança devem priorizar a remediação das falhas críticas e monitorar de perto a evolução do EPSS de CVE-2026-44338 diante da ausência de exploração confirmada, mas contexto de exposição crescente.

CVE-2026-40153HIGHPraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell ToolEPSS 0.3%CVE-2026-55540HIGHPraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinksEPSS 0.3%CVE-2026-55528HIGHpraisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862)EPSS 0.3%CVE-2026-40150HIGHPraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl ToolEPSS 0.3%CVE-2026-55538HIGHPraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticatedEPSS 0.3%CVE-2026-57115MEDIUMPraisonAI: SpiderTools redirect-target SSRF protection bypassEPSS 0.3%CVE-2026-55534HIGHPraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent executionEPSS 0.3%CVE-2026-55531MEDIUMPraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced)EPSS 0.2%CVE-2026-40287HIGHPraisonAI has RCE via Automatic tools.py ImportEPSS 0.2%CVE-2026-44334HIGHPraisonAI: Unauthenticated RCE via `tool_override.py`EPSS 0.2%CVE-2026-40148MEDIUMPraisonAI Affected by Decompression Bomb DoS via Recipe Bundle Extraction Without Size LimitsEPSS 0.2%CVE-2026-40158HIGHPraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonaiEPSS 0.2%CVE-2026-40117MEDIUMPraisonAIAgents Affected by Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval GateEPSS 0.2%CVE-2026-40113HIGHPraisonAI has an Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-varsEPSS 0.2%CVE-2026-40111CRITICALPraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)EPSS 0.2%CVE-2026-40149HIGHPraisonAI has an Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety ControlsEPSS 0.2%CVE-2026-55535MEDIUMPraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validationEPSS 0.2%CVE-2026-44337MEDIUMPraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queriesEPSS 0.2%CVE-2026-40112MEDIUMPraisonAI has Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)EPSS 0.2%CVE-2026-61433HIGHPraisonAI before 4.6.78 Code Injection via API deployment generatorEPSS 0.2%