Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
pkg:npm/
praisonai
9 total CVEs
CRITICAL
4
HIGH
5
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.9
CVE-2026-57138
npm PraisonAI codeMode sandbox escape via Function constructor
>= 1.4.0, < 1.7.2
CRITICAL
9.8
CVE-2026-57139
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
>= 1.5.0, < 1.7.2
CRITICAL
9.8
CVE-2026-57141
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
from 0, < 1.7.2
CRITICAL
9.4
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
>= 1.6.0, < 1.7.2
HIGH
8.8
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
>= 1.5.1, < 1.7.2
HIGH
8.8
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
>= 1.4.0, < 1.7.2
HIGH
8.8
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
>= 1.2.3, < 1.7.2
HIGH
8.2
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
>= 1.5.1, < 1.7.2
HIGH
7.6
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
>= 1.2.3, < 1.7.2
CVE-2026-57140
CVE-2026-57133
CVE-2026-57137
CVE-2026-57136
CVE-2026-57134
CVE-2026-57135
npm/praisonai — 9 CVEs · VulnScope