Description
PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked to reach the model.
Published: 2026-07-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PraisonAI versions prior to 4.6.78 contain a flaw that undermines its prompt injection defense. The defense only blocks threats classified as CRITICAL and requires three or more detector families to match simultaneously. Attackers can craft single or double‑vector prompt injections that receive a HIGH threat rating, allowing them to bypass the filter and reach the underlying model. This can lead to the model processing malicious content or generating unintended outputs.

Affected Systems

MervinPraison’s PraisonAI deployments running any release earlier than 4.6.78 are affected. All installations that have not been patched to at least version 4.6.78 remain vulnerable to prompt injection bypass tests.

Risk and Exploitability

The CVSS score of 6.9 reflects moderate risk, while the EPSS score of < 1% indicates a very low likelihood of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploitation yet. Likely attack vectors involve sending crafted prompt data through the AI’s input channel—via API or web interface—without requiring elevated privileges.

Generated by OpenCVE AI on July 29, 2026 at 10:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 4.6.78 or later to restore the full prompt injection defense.
  • Reconfigure the model’s prompt filter to treat HIGH‑level threats as critical or to block any prompt matches multiple detector families as a precautionary measure.
  • Deploy an external filtering or sandboxing layer that sanitizes user input for injected prompt patterns before it is forwarded to the model.

Generated by OpenCVE AI on July 29, 2026 at 10:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked to reach the model.
Title PraisonAI before 4.6.78 Prompt Injection Defense Bypass
First Time appeared Praison
Praison praisonai
Weaknesses CWE-693
CPEs cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*
Vendors & Products Praison
Praison praisonai
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Praison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T01:46:54.788Z

Reserved: 2026-07-08T12:14:28.344Z

Link: CVE-2026-60086

cve-icon Vulnrichment

Updated: 2026-07-14T01:46:40.098Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:00:13Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure