praisonaiagents@1.6.72

Praison AI agents for completing complex tasks with Self Reflection Agents

  • latest version

    1.6.167

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    2 hours ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the praisonaiagents package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Incorrect Authorization

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Incorrect Authorization via the tool approval process. An attacker can perform unauthorized actions by reusing an initial approval for a benign operation to execute dangerous file write operations with unreviewed parameters in the same session.

    How to fix Incorrect Authorization?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)
    • H
    Directory Traversal

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Directory Traversal via the run_skill_script function. An attacker can execute arbitrary scripts from any location on the filesystem by supplying absolute file paths, bypassing intended directory restrictions.

    How to fix Directory Traversal?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)
    • H
    Arbitrary Code Injection

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Arbitrary Code Injection via the plugin manager process. An attacker can execute arbitrary code by placing a malicious .py file in the plugin directories, which are loaded without code signing, integrity verification, or sandboxing.

    How to fix Arbitrary Code Injection?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)
    • H
    Server-side Request Forgery (SSRF)

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the web_crawl process. An attacker can access internal HTTP response bodies from private or loopback services by exploiting DNS rebinding to bypass hostname validation.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)
    • H
    Improper Check for Dropped Privileges

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Improper Check for Dropped Privileges due to the lack of enforcement of security restrictions in the Subprocess Sandbox backend, including blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write. An attacker can execute arbitrary subprocess commands, access sensitive files, and perform unauthorized operations by bypassing intended security policies.

    How to fix Improper Check for Dropped Privileges?

    Upgrade praisonaiagents to version 1.6.81 or higher.

    [,1.6.81)
    • C
    Arbitrary Code Injection

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Arbitrary Code Injection via the CodeAgent._execute_python function. An attacker can execute arbitrary code and exfiltrate environment secrets by influencing LLM output through prompt injection.

    How to fix Arbitrary Code Injection?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)
    • H
    Server-side Request Forgery (SSRF)

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the Crawl4AI backend process. An attacker can access internal network resources and sensitive information by crafting URLs that exploit DNS rebinding and HTTP redirects, causing the headless browser to follow redirects to internal services.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)
    • H
    Protection Mechanism Failure

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Protection Mechanism Failure in the AgentFlow._resolve_pydantic_class process. An attacker can execute arbitrary Python code with the privileges of the workflow runner by supplying a malicious workflow file and a sibling tools.py file, which are then imported unsafely when the workflow is executed via WorkflowManager or after load_yaml.

    How to fix Protection Mechanism Failure?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)
    • M
    Directory Traversal

    praisonaiagents is a Praison AI agents for completing complex tasks with Self Reflection Agents

    Affected versions of this package are vulnerable to Directory Traversal via the agent.start process. An attacker can overwrite files outside the intended project directory by supplying a malicious .praisonai/config.toml file that sets the output_file path to an absolute or directory traversal value, causing the application to write output to arbitrary locations with the privileges of the user running the process.

    How to fix Directory Traversal?

    Upgrade praisonaiagents to version 1.6.78 or higher.

    [,1.6.78)