Impact
PraisonAI versions prior to 4.6.78 contain a flaw that undermines its prompt injection defense. The defense only blocks threats classified as CRITICAL and requires three or more detector families to match simultaneously. Attackers can craft single or double‑vector prompt injections that receive a HIGH threat rating, allowing them to bypass the filter and reach the underlying model. This can lead to the model processing malicious content or generating unintended outputs.
Affected Systems
MervinPraison’s PraisonAI deployments running any release earlier than 4.6.78 are affected. All installations that have not been patched to at least version 4.6.78 remain vulnerable to prompt injection bypass tests.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate risk, while the EPSS score of < 1% indicates a very low likelihood of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploitation yet. Likely attack vectors involve sending crafted prompt data through the AI’s input channel—via API or web interface—without requiring elevated privileges.
OpenCVE Enrichment