Vulnerabilidades em MervinPraison

112 resultados
Análise Vexday

O portfólio de vulnerabilidades da MervinPraison apresenta um perfil atípico: todas as 53 CVEs catalogadas surgiram nos últimos 90 dias, indicando um produto recente ou uma fila de divulgação concentrada, e nenhuma delas consta no catálogo CISA KEV, taxa abaixo da média geral. Ainda assim, 18 falhas são classificadas como críticas e a falha mais predominante é CWE-22 (Path Traversal), tipo de vulnerabilidade com potencial significativo de impacto em confidencialidade e integridade de dados. A CVE mais perigosa atualmente, CVE-2026-44338, registra EPSS de 0,268, sugerindo probabilidade não negligenciável de exploração em breve, especialmente considerando a existência de ao menos um PoC público no conjunto. Equipes de segurança devem priorizar a remediação das falhas críticas e monitorar de perto a evolução do EPSS de CVE-2026-44338 diante da ausência de exploração confirmada, mas contexto de exposição crescente.

CVE-2026-34952CRITICALPraisonAI: Missing Authentication in WebSocket GatewayEPSS 0.4%CVE-2026-44340HIGHPraisonAI: Symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`EPSS 0.4%CVE-2026-47394HIGHPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validateEPSS 0.4%CVE-2026-40088CRITICALImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonaiEPSS 0.4%CVE-2026-39889HIGHPraisonAI has Unauthenticated SSE Event Stream Exposes All Agent Activity in A2U ServerEPSS 0.4%CVE-2026-35615CRITICALPraisonAI has a Path Traversal in FileToolsEPSS 0.4%CVE-2026-60090CRITICALPraisonAI before 4.6.78 SQL/CQL Injection via vector dimensionEPSS 0.4%CVE-2026-34954HIGHPraisonAI: SSRF in FileTools.download_file() via Unvalidated URLEPSS 0.4%CVE-2026-47393CRITICALPraisonAI `deploy --type api` emits a Flask server with authentication disabled by defaultEPSS 0.4%CVE-2026-34939MEDIUMPraisonAI: ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()EPSS 0.4%CVE-2026-61444CRITICALPraisonAI before 4.6.78 Code Injection via f-stringEPSS 0.4%CVE-2026-61435HIGHPraisonAI before 4.6.78 Authentication Bypass via Host Header SpoofingEPSS 0.4%CVE-2026-34955HIGHPraisonAI: Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandboxEPSS 0.4%CVE-2026-47397HIGHPraisonAI has an Arbitrary File Write in Python APIEPSS 0.4%CVE-2026-40157CRITICALPraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack`EPSS 0.4%CVE-2026-44335HIGHSSRF bypass in PraisonAIEPSS 0.4%CVE-2026-34953CRITICALPraisonAI: Authentication Bypass in OAuthManager.validate_token()EPSS 0.4%CVE-2026-40116HIGHPraisonAI's Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate LimitsEPSS 0.4%CVE-2026-44339HIGHPraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables executeEPSS 0.4%CVE-2026-47410CRITICALpraisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unsetEPSS 0.4%