Mervinpraison

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 111
    Known Exploited: 0
    26
    Critical Level Threats
    59
    High Level Threats
    21
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-55536

    Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

    Last Modified: Aug 28, 2026
    Published: Aug 25, 2026

    CVE-2026-55532

    PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

    Last Modified: Aug 25, 2026
    Published: Aug 25, 2026

    CVE-2026-55533

    PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

    Last Modified: Aug 25, 2026
    Published: Aug 25, 2026

    CVE-2026-55539

    PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

    Last Modified: Aug 25, 2026
    Published: Aug 25, 2026

    CVE-2026-55527

    PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

    Last Modified: Aug 25, 2026
    Published: Aug 25, 2026
    Items Per Page