Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MervinPraison — Vulnerabilities & Security Advisories 108

Browse all 108 CVE security advisories affecting MervinPraison. AI-powered Chinese analysis, POCs, and references for each vulnerability.

mervinpraison is primarily associated with open-source automation and scripting tools, often utilized for system administration and data processing tasks. Security audits have identified forty-five Common Vulnerabilities and Exposures (CVEs) linked to this entity, predominantly stemming from legacy codebases and insufficient input validation. The most frequently observed vulnerability classes include Remote Code Execution (RCE) and Cross-Site Scripting (XSS), which arise from improper sanitization of user-supplied data. Additionally, several instances of insecure direct object references and privilege escalation flaws have been documented, reflecting gaps in access control mechanisms. These issues typically affect older versions of the software suite, with patches available for recent releases. The profile indicates a pattern of reactive security maintenance rather than proactive secure development, necessitating careful version management for users relying on these tools in production environments.

Found 84 results / 108Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-47398 PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334 — PraisonAICWE-94 8.1 High2026-07-21
CVE-2026-47397 PraisonAI has an Arbitrary File Write in Python API — PraisonAICWE-22 7.1 High2026-07-21
CVE-2026-47396 PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset — PraisonAICWE-284 9.8 Critical2026-07-21
CVE-2026-47395 PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context — PraisonAICWE-200 5.5 Medium2026-07-21
CVE-2026-47394 PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate — PraisonAICWE-22--2026-07-21
CVE-2026-47393 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default — PraisonAICWE-306 9.8 Critical2026-07-21
CVE-2026-47392 PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode) — PraisonAICWE-184 9.9 Critical2026-07-21
CVE-2026-47391 PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution — PraisonAICWE-95 9.8 Critical2026-07-21
CVE-2026-47390 PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings — PraisonAICWE-918 5.5 Medium2026-07-21
CVE-2026-61446 PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery — PraisonAICWE-94 8.4 High2026-07-15
CVE-2026-61443 PraisonAI before 1.6.78 Remote Code Execution via SkillTools — PraisonAICWE-22 8.1 High2026-07-15
CVE-2026-61440 PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints — PraisonAICWE-862 6.5 Medium2026-07-15
CVE-2026-61438 PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox — PraisonAICWE-78 7.3 High2026-07-15
CVE-2026-61436 PraisonAI before 4.6.78 Missing Webhook Signature Verification — PraisonAICWE-287 8.6 High2026-07-15
CVE-2026-61435 PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing — PraisonAICWE-287 8.2 High2026-07-15
CVE-2026-61433 PraisonAI before 4.6.78 Code Injection via API deployment generator — PraisonAICWE-94 7.8 High2026-07-15
CVE-2026-61430 PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl — PraisonAICWE-918 8.5 High2026-07-15
CVE-2026-61427 PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream — PraisonAICWE-20 7.3 High2026-07-15
CVE-2026-60087 PraisonAI before 1.6.78 Tool Approval Cache Bypass — PraisonAICWE-863 6.1 Medium2026-07-15
CVE-2026-60085 PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox — PraisonAICWE-273 7.5 High2026-07-15
CVE-2026-61447 PraisonAI before 1.6.78 Remote Code Execution via CodeAgent — PraisonAICWE-94 10.0 Critical2026-07-11
CVE-2026-61445 PraisonAI before 4.6.78 Arbitrary File Write and Command Execution — PraisonAICWE-22 9.9 Critical2026-07-11
CVE-2026-61442 PraisonAI Platform before 0.1.9 Authorization Bypass via PATCH — PraisonAICWE-862 7.1 High2026-07-11
CVE-2026-61439 PraisonAI before 4.6.78 Prompt Injection Defense Bypass — PraisonAICWE-1188 7.5 High2026-07-11
CVE-2026-61428 PraisonAI AgentMail before 4.6.78 Message Injection via Webhook — PraisonAICWE-290 7.3 High2026-07-11
CVE-2026-61429 PraisonAI before 1.6.78 SSRF via Crawl4AI Chromium backend — PraisonAICWE-918 8.5 High2026-07-11
CVE-2026-61426 PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults — PraisonAICWE-200 8.6 High2026-07-11
CVE-2026-60088 PraisonAI before 4.6.78 Path Traversal via Custom Commands — PraisonAICWE-22 5.5 Medium2026-07-11
CVE-2026-60090 PraisonAI before 4.6.78 SQL/CQL Injection via vector dimension — PraisonAICWE-89 9.8 Critical2026-07-11
CVE-2026-61444 PraisonAI before 4.6.78 Code Injection via f-string — PraisonAICWE-94 9.1 Critical2026-07-10

This page lists every published CVE security advisory associated with MervinPraison. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.