Impact
PraisonAI versions prior to 4.6.78 contain a configuration flaw in the prompt injection defense that leaves the block threshold set to CRITICAL severity. When a high‑severity prompt injection is submitted, the system logs the event but does not block it, so the injected text is processed and stored. This allows attackers to extract system prompts, glean internal instructions, and launch unauthorized tool invocations, effectively compromising the integrity of the AI responses. The weakness is classified as CWE‑1188, a configuration error.
Affected Systems
MervinPraison’s PraisonAI product, specifically all versions released before 4.6.78. Users running these affected releases should verify their installed version; any earlier releases are impacted.
Risk and Exploitability
The vulnerability scored 8.7 on the CVSS scale, indicating high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the issue is not listed in CISA’s KEV catalog. Although exploitation is unlikely, the potential impact is substantial because malicious prompts can be submitted through any interface that accepts user input. The attack vector is inferred to remote, via the system’s prompt submission channel, without requiring elevated privileges or special access. Once exploited, the attacker can read internal prompts and trigger actions that the AI would otherwise block, resulting in data leakage or unintended operations.
OpenCVE Enrichment