4.6.162
2 years ago
2 days ago
Known vulnerabilities in the praisonai package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Improper Authentication via the How to fix Improper Authentication? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Improper Authentication via the How to fix Improper Authentication? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Command Injection via insufficient validation in the How to fix Command Injection? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Improper Check for Dropped Privileges due to the lack of enforcement of security restrictions in the How to fix Improper Check for Dropped Privileges? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Improper Input Validation via the How to fix Improper Input Validation? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Arbitrary Code Injection via the How to fix Arbitrary Code Injection? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Insecure Default Initialization of Resource due to a misconfiguration in the prompt injection defense threshold, which defaults to blocking only CRITICAL severity threats. An attacker can bypass intended security controls by submitting prompt injection attacks that trigger HIGH severity detections, resulting in unauthorized access to system prompts and invocation of restricted tools. How to fix Insecure Default Initialization of Resource? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to User Impersonation due to missing signature verification in the webhook process. An attacker can inject arbitrary messages and trigger replies to attacker-controlled addresses by sending crafted POST requests to the webhook endpoint, effectively bypassing sender allow/block lists. How to fix User Impersonation? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the How to fix Server-side Request Forgery (SSRF)? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Command Injection in the How to fix Command Injection? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Arbitrary Code Injection via the How to fix Arbitrary Code Injection? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,4.6.65) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Protection Mechanism Failure due to insufficient enforcement in the How to fix Protection Mechanism Failure? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,4.6.81) |
PraisonAI is a PraisonAI is an AI Agents Framework with Self Reflection. PraisonAI application combines PraisonAI Agents, AutoGen, and CrewAI into a low-code solution for building and managing multi-agent LLM systems, focusing on simplicity, customisation, and efficient human-agent collaboration. Affected versions of this package are vulnerable to Directory Traversal via the processing of custom command templates that fail to validate file path references. An attacker can access files outside the intended workspace by including path traversal sequences or absolute paths in project command files. How to fix Directory Traversal? Upgrade | [,4.6.81) |