Vulnerabilidades em mervinpraison

158 resultados
Análise Vexday

Mervinpraison apresenta perfil de risco mínimo com apenas 1 CVE catalogada na base, sem evidência de exploração ativa (KEV) ou severidade crítica. A vulnerabilidade identificada refere-se a XSS (CWE-79) e não foi publicada nos últimos 90 dias, indicando que não há risco recente imediato associado a este fornecedor.

CVE-2026-47397HIGHPraisonAI has an Arbitrary File Write in Python APIEPSS 0.5%CVE-2026-61442HIGHPraisonAI Platform before 0.1.9 Authorization Bypass via PATCHEPSS 0.5%CVE-2026-34952CRITICALPraisonAI: Missing Authentication in WebSocket GatewayEPSS 0.4%CVE-2026-57129HIGHPraisonAI: Arbitrary File Read via `@file:` Mention Path TraversalEPSS 0.4%CVE-2026-57133HIGHPraisonAI utility shell safe-command wrapper allowlist bypass via shell chainingEPSS 0.4%CVE-2026-44340HIGHPraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`EPSS 0.4%CVE-2026-61439HIGHPraisonAI before 4.6.78 Prompt Injection Defense BypassEPSS 0.4%CVE-2026-40088CRITICALImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonaiEPSS 0.4%CVE-2026-57139CRITICALPraisonAI MCPServer exposes unauthenticated HTTP tools/callEPSS 0.4%CVE-2026-39889HIGHPraisonAI has Unauthenticated SSE Event Stream Exposes All Agent Activity in A2U ServerEPSS 0.4%CVE-2026-35615CRITICALPraisonAI has a Path Traversal in FileToolsEPSS 0.4%CVE-2026-47407CRITICALPraisonAI Platform has a cross-workspace IDOR + member-role privilege escalationEPSS 0.4%CVE-2026-57125CRITICALPraisonAI: Unauthenticated RCE via Jobs API + Approval BypassEPSS 0.4%CVE-2026-47418HIGHpraisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOREPSS 0.4%CVE-2026-61441HIGHPraisonAI Platform before 0.1.9 Authorization Bypass via DependenciesEPSS 0.4%CVE-2026-47406HIGHpraisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOREPSS 0.4%CVE-2026-60085HIGHPraisonAI before 4.6.78 Unenforced Security Policy in Subprocess SandboxEPSS 0.4%CVE-2026-61432MEDIUMPraisonAI FastContext before 1.6.78 Path TraversalEPSS 0.4%CVE-2026-34954HIGHPraisonAI: SSRF in FileTools.download_file() via Unvalidated URLEPSS 0.4%CVE-2026-47408MEDIUMpraisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownershipEPSS 0.4%