Vulnerabilidades en mervinpraison
158 resultadosAnálisis Vexday
Mervinpraison apresenta perfil de risco mínimo com apenas 1 CVE catalogada na base, sem evidência de exploração ativa (KEV) ou severidade crítica. A vulnerabilidade identificada refere-se a XSS (CWE-79) e não foi publicada nos últimos 90 dias, indicando que não há risco recente imediato associado a este fornecedor.
CVE-2026-40153HIGHPraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell ToolEPSS 0.3%CVE-2026-55540HIGHPraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinksEPSS 0.3%CVE-2026-55528HIGHpraisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862)EPSS 0.3%CVE-2026-40150HIGHPraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl ToolEPSS 0.3%CVE-2026-55538HIGHPraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticatedEPSS 0.3%CVE-2026-57115MEDIUMPraisonAI: SpiderTools redirect-target SSRF protection bypassEPSS 0.3%CVE-2026-55534HIGHPraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent executionEPSS 0.3%CVE-2026-55531MEDIUMPraisonAI: Unauthenticated unbounded session accumulation in the PraisonAI MCP HTTP server (memory exhaustion; session TTL never enforced)EPSS 0.2%CVE-2026-40287HIGHPraisonAI has RCE via Automatic tools.py ImportEPSS 0.2%CVE-2026-44334HIGHPraisonAI: Unauthenticated RCE via `tool_override.py`EPSS 0.2%CVE-2026-40148MEDIUMPraisonAI Affected by Decompression Bomb DoS via Recipe Bundle Extraction Without Size LimitsEPSS 0.2%CVE-2026-40158HIGHPraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonaiEPSS 0.2%CVE-2026-40117MEDIUMPraisonAIAgents Affected by Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval GateEPSS 0.2%CVE-2026-40113HIGHPraisonAI has an Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-varsEPSS 0.2%CVE-2026-40111CRITICALPraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)EPSS 0.2%CVE-2026-40149HIGHPraisonAI has an Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety ControlsEPSS 0.2%CVE-2026-55535MEDIUMPraisonAI: Server-Side Request Forgery via DNS rebinding bypass in webhook_url validationEPSS 0.2%CVE-2026-44337MEDIUMPraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queriesEPSS 0.2%CVE-2026-40112MEDIUMPraisonAI has Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)EPSS 0.2%CVE-2026-61433HIGHPraisonAI before 4.6.78 Code Injection via API deployment generatorEPSS 0.2%