检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5JV7-2MJM-H6QJ CVE-2026-57133 | npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining | 高危 | npmpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:28 |
| GHSA-H2W2-V7J6-XQM4 CVE-2026-57137 | npm PraisonAI AgentLoop onToolCall approval runs after tool execution |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmpraisonai |
| 已审查 |
| 2026-06-18 22:26 |
| 2026-07-21 05:27 |
| GHSA-J4F3-55X4-R6Q2 CVE-2026-57139 | npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call | 严重 | npmpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:27 |
| GHSA-9752-MHQH-H34F CVE-2026-57140 | npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation | 严重 | npmpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:27 |
| GHSA-P69M-4F92-2V84 CVE-2026-57141 | PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool | 严重 | npmpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:27 |
| GHSA-VJV9-7M7J-H833 CVE-2026-57136 | npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining | 高危 | npmpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:27 |
| GHSA-VMMJ-PFW7-FJWP CVE-2026-57138 | npm PraisonAI codeMode sandbox escape via Function constructor | 严重 | npmpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:27 |
| GHSA-GQMF-56H7-RRPF CVE-2026-57135 | npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients | 高危 | npmpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:27 |
| GHSA-4QQ2-2J2X-X62C CVE-2026-57134 | npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation | 高危 | npmpraisonai | 已审查 | 2026-06-18 22:25 | 2026-07-21 05:27 |
| GHSA-C969-5X3P-VQ3V CVE-2026-57130 | PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters | 高危 | PyPIpraisonaiagents | 已审查 | 2026-06-18 22:25 | 2026-07-21 05:26 |
| GHSA-F44V-7QGW-9GH9 CVE-2026-57113 | PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 22:24 | 2026-07-21 05:24 |
| GHSA-4JGR-PG2M-M988 CVE-2026-57209 | Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode | 高危 | Gogithub.com/dadrus/heimdall | 已审查 | 2026-06-18 22:24 | 2026-07-21 05:28 |
| GHSA-38X9-25WX-7FG2 CVE-2026-57210 | Heimdall: IP Spoofing via Unvalidated Forwarding Headers | 高危 | Gohttps://github.com/dadrus/heimdall | 已审查 | 2026-06-18 22:24 | 2026-07-21 05:28 |
| GHSA-GCQ3-MFVH-3X25 CVE-2026-56839 | PraisonAI Code agent tools fail open without a workspace boundary | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 21:59 | 2026-07-21 05:23 |
| GHSA-P75F-6FP4-P57W CVE-2026-57124 | PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai | 严重 | PyPIpraisonai | 已审查 | 2026-06-18 21:58 | 2026-07-21 05:25 |
| GHSA-X92V-RPX6-P6CW CVE-2026-57122 | PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots) | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 21:58 | 2026-07-21 05:25 |
| GHSA-RH39-9C67-59MH CVE-2026-57121 | PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API | 高危 | PyPIpraisonai-platform | 已审查 | 2026-06-18 21:58 | 2026-07-21 05:25 |
| GHSA-892R-P3JQ-JP24 CVE-2026-57116 | PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation | 严重 | PyPIpraisonai | 已审查 | 2026-06-18 21:57 | 2026-07-21 05:24 |
| GHSA-X8CV-XMQ7-P8XP CVE-2026-57118 | PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints | 严重 | PyPIpraisonaiagents | 已审查 | 2026-06-18 21:57 | 2026-07-21 05:24 |
| GHSA-RJVW-7VVW-549V CVE-2026-57114 | PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 21:57 | 2026-07-21 05:24 |
| GHSA-FQ2M-6WQH-X44G CVE-2026-57131 | PraisonAI: Jobs API exposes agent-execution endpoints with no authentication | 严重 | PyPIpraisonai | 已审查 | 2026-06-18 21:57 | 2026-07-21 05:26 |
| GHSA-2RCG-MM5H-XCHX CVE-2026-57129 | PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal | 高危 | PyPIpraisonaiagents | 已审查 | 2026-06-18 21:57 | 2026-07-21 05:26 |
| GHSA-J4HJ-7HFH-G2F4 CVE-2026-57127 | praisonai: recipe serve auth middleware silently disables itself when no secret is set | 严重 | PyPIpraisonai | 已审查 | 2026-06-18 21:56 | 2026-07-21 05:25 |
| GHSA-VXGJ-XG5C-P4H7 CVE-2026-57126 | praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS | 高危 | PyPIpraisonaiagents | 已审查 | 2026-06-18 21:56 | 2026-07-21 05:25 |
| GHSA-4869-X4PR-Q22X CVE-2026-57125 | PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass | 严重 | PyPIpraisonai+1 | 已审查 | 2026-06-18 21:56 | 2026-07-21 05:25 |