目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-47397— PraisonAI Python API 任意文件写入漏洞

AI Predicted 9.1 Difficulty: Easy EPSS 0.05% · P17

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
MervinPraisonPraisonAI< 4.6.40affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-47397の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
PraisonAI has an Arbitrary File Write in Python API
ソース: NVD (National Vulnerability Database)
脆弱性説明
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path validation when `workspace=None` (always `None` in production). Version 4.6.40 fixes the issue.
ソース: NVD (National Vulnerability Database)
CVSS情報
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
对路径名的限制不恰当(路径遍历)
ソース: NVD (National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
MervinPraisonPraisonAI < 4.6.40 -

II. CVE-2026-47397の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-47397のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-47397 厂商安全公告 (1)

Same Patch Batch · MervinPraison · 2026-07-21 · 25 CVEs total

CVE-2026-473929.9 CRITICALPraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execu
CVE-2026-473939.8 CRITICALPraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-473969.8 CRITICALPraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when
CVE-2026-473919.8 CRITICALPraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool e
CVE-2026-474109.8 CRITICALpraisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing
CVE-2026-474139.6 CRITICALpraisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspa
CVE-2026-474169.6 CRITICALpraisonai-platform: Any workspace member can promote themselves (or any other member) to o
CVE-2026-474058.8 HIGHPraisonAI Platform missing role checks let any workspace member become owner and take over
CVE-2026-473998.8 HIGHPraisonAI Platform workspace-scoped routes allow cross-workspace object access by global o
CVE-2026-474158.3 HIGHpraisonai-platform: Issue endpoints accept any issue_id without workspace ownership check,
CVE-2026-474198.3 HIGHpraisonai-platform: Agent endpoints accept any agent_id without workspace ownership check,
CVE-2026-474098.1 HIGHpraisonai-platform: Any workspace member can remove any other member (including the owner)
CVE-2026-474178.1 HIGHpraisonai-platform: Comment endpoints accept any issue_id without workspace ownership chec
CVE-2026-474128.1 HIGHpraisonai-platform: Any workspace member can delete the entire workspace via DELETE /works
CVE-2026-474188.1 HIGHpraisonai-platform: Project endpoints accept any project_id without workspace ownership ch
CVE-2026-474068.1 HIGHpraisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace
CVE-2026-473988.1 HIGHPraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_gen
CVE-2026-474147.6 HIGHpraisonai-platform: Label endpoints accept any label_id and any issue_id without workspace
CVE-2026-474086.5 MEDIUMpraisonai-platform: list_issue_activity returns activity log for any issue regardless of w
CVE-2026-474116.5 MEDIUMpraisonai-platform: Any workspace member can rewrite workspace name, description, and sett

Showing 20 of 25 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-47397へのコメント

まだコメントはありません


コメントを残す