Vulnerabilidades em MervinPraison

158 resultados
Análise Vexday

O portfólio de vulnerabilidades da MervinPraison apresenta um perfil atípico: todas as 53 CVEs catalogadas surgiram nos últimos 90 dias, indicando um produto recente ou uma fila de divulgação concentrada, e nenhuma delas consta no catálogo CISA KEV, taxa abaixo da média geral. Ainda assim, 18 falhas são classificadas como críticas e a falha mais predominante é CWE-22 (Path Traversal), tipo de vulnerabilidade com potencial significativo de impacto em confidencialidade e integridade de dados. A CVE mais perigosa atualmente, CVE-2026-44338, registra EPSS de 0,268, sugerindo probabilidade não negligenciável de exploração em breve, especialmente considerando a existência de ao menos um PoC público no conjunto. Equipes de segurança devem priorizar a remediação das falhas críticas e monitorar de perto a evolução do EPSS de CVE-2026-44338 diante da ausência de exploração confirmada, mas contexto de exposição crescente.

CVE-2026-44338HIGHPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow executionEPSS 28.6%CVE-2026-34938CRITICALPraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_codeEPSS 13.2%CVE-2026-61447CRITICALPraisonAI before 1.6.78 Remote Code Execution via CodeAgentEPSS 2.5%CVE-2026-47391CRITICALPraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool executionEPSS 1.2%CVE-2026-57131CRITICALpraisonai: Jobs API exposes agent-execution endpoints with no authenticationEPSS 1.0%CVE-2026-48168CRITICALPraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch nameEPSS 0.9%CVE-2026-57127CRITICALpraisonai: recipe serve auth middleware silently disables itself when no secret is setEPSS 0.9%CVE-2026-47392CRITICALPraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)EPSS 0.9%CVE-2026-61445CRITICALPraisonAI before 4.6.78 Arbitrary File Write and Command ExecutionEPSS 0.9%CVE-2026-61434HIGHPraisonAI before 4.6.78 Allowlist Bypass via find -execEPSS 0.9%CVE-2026-34935CRITICALPraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()EPSS 0.8%CVE-2026-47393CRITICALPraisonAI `deploy --type api` emits a Flask server with authentication disabled by defaultEPSS 0.8%CVE-2026-57147CRITICALpraisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgeryEPSS 0.8%CVE-2026-61443HIGHPraisonAI before 1.6.78 Remote Code Execution via SkillToolsEPSS 0.8%CVE-2026-40151MEDIUMPraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOSEPSS 0.8%CVE-2026-60090CRITICALPraisonAI before 4.6.78 SQL/CQL Injection via vector dimensionEPSS 0.7%CVE-2026-61435HIGHPraisonAI before 4.6.78 Authentication Bypass via Host Header SpoofingEPSS 0.7%CVE-2026-57124CRITICALPraisonAI UI MCP connect endpoint allows unauthenticated local command executionEPSS 0.6%CVE-2026-47396CRITICALPraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unsetEPSS 0.6%CVE-2026-47410CRITICALpraisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unsetEPSS 0.6%