Praison AI agents for completing complex tasks with Self Reflection Agents
praisonaiagents has critical vulnerabilities — do not use
Update to >= 4.5.128 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | CVE-2026-40289 | PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions | 4.5.139 |
| medium | GHSA-ffp3-3562-8cv3 | PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands | 4.5.128 |
| high | CVE-2026-40287 | PraisonAI Vulnerable to RCE via Automatic tools.py Import | 4.5.139 |
| critical | CVE-2026-40288 | PraisonAI has critical RCE via `type: job` workflow YAML | 4.5.139 |
| high | GHSA-x462-jjpc-q4q4 | PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint | 4.5.128 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/pypi/praisonaiagentsLast updated · 2026-05-03T05:23:00.617738Z