Multiple critical vulnerabilities in PraisonAI multi-agent framework (8 CVEs)
Eight CVEs disclosed in April 2026 affect the PraisonAI and PraisonAIAgents multi-agent frameworks, including an MCP authentication bypass accepting any bearer token, shell command injection via agent workflows and lifecycle hooks, arbitrary file read, SSRF in web crawl tools, unsanitized HTML output enabling XSS, and full environment-variable inheritance by MCP subprocesses that can leak API keys. Several are exploitable through prompt injection and all are fixed in versions 4.5.97/4.5.121/4.5.128 and 1.5.128.
Disclosed 3 April 2026 · Record updated 13 September 2026
Impact
Unauthenticated access to all registered MCP tools and agent capabilities, arbitrary shell command execution, arbitrary file reads and exfiltration, SSRF to cloud metadata and internal services, stored XSS in API output, and exposure of API keys and credentials to spawned MCP subprocesses.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-34953
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40088
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40111
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40112
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40117
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40150
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40159
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-40160
