Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86818 | MEDIUM | 4.8 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In … | Sep 15, 2026 |
| CVE-2026-86472 | MEDIUM | 4.8 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from … | Sep 15, 2026 |
| CVE-2026-80489 | MEDIUM | 5.9 | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 … | Sep 15, 2026 |
| CVE-2026-77117 | MEDIUM | 5.9 | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 … | Sep 15, 2026 |
| CVE-2026-57148 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the … | Sep 15, 2026 |
| CVE-2026-57147 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard … | Sep 15, 2026 |
| CVE-2026-57141 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression … | Sep 15, 2026 |
| CVE-2026-57140 | CRITICAL | 9.4 | PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST … | Sep 15, 2026 |
| CVE-2026-57139 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to … | Sep 15, 2026 |
| CVE-2026-57138 | CRITICAL | 9.9 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a … | Sep 15, 2026 |
| CVE-2026-57137 | HIGH | 8.8 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because … | Sep 15, 2026 |
| CVE-2026-57136 | HIGH | 8.8 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the … | Sep 15, 2026 |
| CVE-2026-57135 | HIGH | 7.6 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment … | Sep 15, 2026 |
| CVE-2026-57134 | HIGH | 8.2 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. … | Sep 15, 2026 |
| CVE-2026-57133 | HIGH | 8.8 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and … | Sep 15, 2026 |
| CVE-2026-57112 | HIGH | 8.3 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse … | Sep 15, 2026 |
| CVE-2026-52828 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and … | Sep 15, 2026 |
| CVE-2026-52827 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every … | Sep 15, 2026 |
| CVE-2026-52826 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier … | Sep 15, 2026 |
| CVE-2026-52825 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do … | Sep 15, 2026 |
| CVE-2026-52824 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh … | Sep 15, 2026 |
| CVE-2026-52823 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform … | Sep 15, 2026 |
| CVE-2026-52822 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from … | Sep 15, 2026 |
| CVE-2026-52821 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project … | Sep 15, 2026 |
| CVE-2026-52820 | UNKNOWN | — | Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and … | Sep 15, 2026 |