Vulnerabilidades en mervinpraison

158 resultados
Análisis Vexday

Mervinpraison apresenta perfil de risco mínimo com apenas 1 CVE catalogada na base, sem evidência de exploração ativa (KEV) ou severidade crítica. A vulnerabilidade identificada refere-se a XSS (CWE-79) e não foi publicada nos últimos 90 dias, indicando que não há risco recente imediato associado a este fornecedor.

CVE-2026-44336CRITICALPraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injectionEPSS 0.6%CVE-2026-40288CRITICALPraisonAI: Critical RCE via `type: job` workflow YAMLEPSS 0.6%CVE-2026-39890CRITICALPraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition LoadingEPSS 0.6%CVE-2026-47398HIGHPraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334EPSS 0.6%CVE-2026-61444CRITICALPraisonAI before 4.6.78 Code Injection via f-stringEPSS 0.6%CVE-2026-39891HIGHPraisonAI has a Template Injection in Agent Tool DefinitionsEPSS 0.6%CVE-2026-34937HIGHPraisonAI: Shell Injection in run_python() via Unescaped $() SubstitutionEPSS 0.5%CVE-2026-41497CRITICALIncomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAIEPSS 0.5%CVE-2026-34934CRITICALPraisonAI: Second-Order SQL Injection in `get_all_user_threads`EPSS 0.5%CVE-2026-47412HIGHpraisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}EPSS 0.5%CVE-2026-47409HIGHpraisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}EPSS 0.5%CVE-2026-57141CRITICALPraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` ToolEPSS 0.5%CVE-2026-61436HIGHPraisonAI before 4.6.78 Missing Webhook Signature VerificationEPSS 0.5%CVE-2026-47405HIGHPraisonAI Platform missing role checks let any workspace member become owner and take over workspace membershipEPSS 0.5%CVE-2026-47399HIGHPraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object IDEPSS 0.5%CVE-2026-47394HIGHPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validateEPSS 0.5%CVE-2025-12019MEDIUMFeatured Image <= 2.1 - Authenticated (Admin+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-61426HIGHPraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure DefaultsEPSS 0.5%CVE-2026-39888CRITICALPraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)EPSS 0.5%CVE-2026-57123CRITICALPraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired inEPSS 0.5%