PT-2026-57188 · Praisonai · Praisonai

·

CVE-2026-60086

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.78
Description A prompt injection defense bypass exists because the system only blocks threats classified as CRITICAL, which requires three or more detector families to match simultaneously. This allows attackers to use single or double-vector prompt injections that are classified as HIGH threat level to bypass the defense and reach the model.
Recommendations Update PraisonAI to version 4.6.78 or later.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60086
GHSA-4R3P-W3MC-5V34

Affected Products

Praisonai