PraisonAI vulnerabilities
3 CVEs tracked
PraisonAI appears in our recent reporting with multiple critical vulnerabilities. Key themes involve command injection via unsanitized input in GitHub Actions workflows (CVE-2026-48168), code execution through the workflow 'include' feature (CVE-2026-55522), and broken workspace isolation due to authorization failures in the Platform API (CVE-2026-48169). Defenders should prioritize: upgrading PraisonAI to versions beyond the vulnerable ranges (especially 4.6.40+), enforcing strict input validation for branch names used in CI/CD pipelines, and verifying that proper workspace-level access controls are enforced in the Platform API.
Azərbaycanca: PraisonAI son hesabatlarımızda çoxsaylı kritik zəifliklərlə bağlı qeyd olunur. Əsas mövzular GitHub Actions workflow-da komanda inyeksiyası (CVE-2026-48168), iş axını daxiletmə funksiyasında kod icrası (CVE-2026-55522) və API-də workspace izolyasiyasını pozan avtorizasiya çatışmazlıqlarıdır (CVE-2026-48169). Müdafiəçilər diqqət yetirməlidirlər: PraisonAI sistemini ən son versiyalara yeniləmək (xüsusilə 4.6.40 və yuxarısı), GitHub Actions workflow-larda işlədilən branch adlarının ciddi validasiyası, həmçinin PraisonAI Platform API-də workspace səviyyəli giriş nəzarətinin düzgün tətbiq olunması.
This vendor's CVEs3
This hub is built from skopnix's own reporting on PraisonAI: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.