Vulnerabilidades em MervinPraison

112 resultados
Análise Vexday

O portfólio de vulnerabilidades da MervinPraison apresenta um perfil atípico: todas as 53 CVEs catalogadas surgiram nos últimos 90 dias, indicando um produto recente ou uma fila de divulgação concentrada, e nenhuma delas consta no catálogo CISA KEV, taxa abaixo da média geral. Ainda assim, 18 falhas são classificadas como críticas e a falha mais predominante é CWE-22 (Path Traversal), tipo de vulnerabilidade com potencial significativo de impacto em confidencialidade e integridade de dados. A CVE mais perigosa atualmente, CVE-2026-44338, registra EPSS de 0,268, sugerindo probabilidade não negligenciável de exploração em breve, especialmente considerando a existência de ao menos um PoC público no conjunto. Equipes de segurança devem priorizar a remediação das falhas críticas e monitorar de perto a evolução do EPSS de CVE-2026-44338 diante da ausência de exploração confirmada, mas contexto de exposição crescente.

CVE-2026-44338HIGHPraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow executionEPSS 28.6%CVE-2026-34938CRITICALPraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_codeEPSS 1.3%CVE-2026-48168CRITICALPraisonAI: GitHub Actions Claude workflow command injection via unquoted PR branch nameEPSS 0.9%CVE-2026-34935CRITICALPraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()EPSS 0.8%CVE-2026-47391CRITICALPraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool executionEPSS 0.8%CVE-2026-40151MEDIUMPraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOSEPSS 0.8%CVE-2026-61447CRITICALPraisonAI before 1.6.78 Remote Code Execution via CodeAgentEPSS 0.7%CVE-2026-44336CRITICALPraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injectionEPSS 0.6%CVE-2026-40288CRITICALPraisonAI: Critical RCE via `type: job` workflow YAMLEPSS 0.6%CVE-2026-47392CRITICALPraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)EPSS 0.6%CVE-2026-39890CRITICALPraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition LoadingEPSS 0.6%CVE-2026-61434HIGHPraisonAI before 4.6.78 Allowlist Bypass via find -execEPSS 0.6%CVE-2026-39891HIGHPraisonAI has a Template Injection in Agent Tool DefinitionsEPSS 0.6%CVE-2026-34937HIGHPraisonAI: Shell Injection in run_python() via Unescaped $() SubstitutionEPSS 0.5%CVE-2026-41497CRITICALIncomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAIEPSS 0.5%CVE-2026-61445CRITICALPraisonAI before 4.6.78 Arbitrary File Write and Command ExecutionEPSS 0.5%CVE-2026-34934CRITICALPraisonAI: Second-Order SQL Injection in `get_all_user_threads`EPSS 0.5%CVE-2026-61443HIGHPraisonAI before 1.6.78 Remote Code Execution via SkillToolsEPSS 0.5%CVE-2025-12019MEDIUMFeatured Image <= 2.1 - Authenticated (Admin+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-39888CRITICALPraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)EPSS 0.5%