Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-61439: PraisonAI versions before 4.6.78 allow high threats to pass through unblocked
CVE-2026-61439
Summary
If you're using PraisonAI, a security misconfiguration in older versions (before 4.6.78) could allow malicious prompts to bypass certain security checks. This means that attackers might be able to manipulate your system or steal sensitive information. To fix this, please update to version 4.6.78 or later.
Original title
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. ...
Original description
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.
nvd CVSS3.1
7.5
nvd CVSS4.0
8.7
Vulnerability type
CWE-1188
Published: 11 Jul 2026 · Updated: 17 Jul 2026 · First seen: 11 Jul 2026