CVE-2026-61439

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.
Configurations

No configuration.

History

14 Jul 2026, 15:17

Type Values Removed Values Added
References () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-fj8f-m44g-c479 - () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-fj8f-m44g-c479 -

11 Jul 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-11 14:16

Updated : 2026-07-14 15:17


NVD link : CVE-2026-61439

Mitre link : CVE-2026-61439

CVE.ORG link : CVE-2026-61439


JSON object : View

Products Affected

No product.

CWE
CWE-1188

Insecure Default Initialization of Resource