Vulnerabilidades em mervinpraison
158 resultadosAnálise Vexday
Mervinpraison apresenta perfil de risco mínimo com apenas 1 CVE catalogada na base, sem evidência de exploração ativa (KEV) ou severidade crítica. A vulnerabilidade identificada refere-se a XSS (CWE-79) e não foi publicada nos últimos 90 dias, indicando que não há risco recente imediato associado a este fornecedor.
CVE-2026-44339HIGHPraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables executeEPSS 0.4%CVE-2026-47417HIGHpraisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOREPSS 0.4%CVE-2026-55523HIGHPraisonAI has a`web_crawl` SSRF protection bypass via unchecked redirect targetsEPSS 0.4%CVE-2026-57145CRITICALPraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path ValidationEPSS 0.4%CVE-2026-57119HIGHPraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs APIEPSS 0.4%CVE-2026-60086MEDIUMPraisonAI before 4.6.78 Prompt Injection Defense BypassEPSS 0.4%CVE-2026-57137HIGHPraisonAI AgentLoop onToolCall approval runs after tool executionEPSS 0.4%CVE-2026-40160HIGHPraisonAIAgents has SSRF via unvalidated URL in `web_crawl` httpx fallbackEPSS 0.4%CVE-2026-40289CRITICALPraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessionsEPSS 0.4%CVE-2026-61431MEDIUMPraisonAI before 4.6.78 Path Traversal via ContextGathererEPSS 0.4%CVE-2026-61429HIGHPraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backendEPSS 0.3%CVE-2026-61430HIGHPraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawlEPSS 0.3%CVE-2026-57130HIGHPraisonAI: IMAP Command Injection via Unsanitized Email Search ParametersEPSS 0.3%CVE-2026-41496HIGHPraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)EPSS 0.3%CVE-2026-34936HIGHPraisonAI: SSRF via Unvalidated api_base in passthrough() FallbackEPSS 0.3%CVE-2026-55533HIGHPraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secretEPSS 0.3%CVE-2026-47411MEDIUMpraisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}EPSS 0.3%CVE-2026-40115MEDIUMPraisonAI has an Unrestricted Upload Size in WSGI Recipe Registry Server Enables Memory Exhaustion DoSEPSS 0.3%CVE-2026-39308HIGHPraisonAI recipe registry publish path traversal allows out-of-root file writeEPSS 0.3%CVE-2026-61446HIGHPraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-DiscoveryEPSS 0.3%