PraisonAI is vulnerable to Remote Code Execution (RCE)
92
Critical Risk
Affected versions of this package contain multiple critical security vulnerabilities, including insufficient protection against SQL injection due to improper use of parameterized queries, inadequate validation leading to path traversal, lack of safeguards against server-side request forgery (SSRF), and improper input sanitization that allows command injection. These issues may enable attackers to access or manipulate sensitive data, interact with internal services, or execute arbitrary commands on the host system.
You are affected if you are using a version which is within vulnerability ranges.
PraisonAI is vulnerable to Remote Code Execution (RCE) in versions 0.0.1 - 2.2.36.
Upgrade the PraisonAI library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant