Oct 7, 2026·7 min read·4 visits
PraisonAI versions before 4.6.78 contain an insecure default configuration in the InjectionDefense component, allowing high-severity prompt injections to bypass active blocking controls.
This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.
PraisonAI is an open-source, multi-agent framework designed to orchestrate autonomous Large Language Model (LLM) agents. In modern LLM applications, user inputs often interact directly with the underlying models, creating a substantial attack surface. To protect these agents from malicious user prompts, PraisonAI implements a dedicated security module known as InjectionDefense. This component is designed to inspect incoming text, evaluate threats across multiple heuristics, and block inputs that present security risks.
In versions of PraisonAI prior to 4.6.78, this protection mechanism was compromised by an insecure default configuration. While the InjectionDefense engine successfully scanned incoming text and classified security risks, its blocking mechanism was configured to trigger only on the highest threat tier. Specifically, the default threshold was set to ThreatLevel.CRITICAL, which meant that highly dangerous, high-severity prompt injections were allowed to reach the downstream LLM.
This vulnerability is classified as CWE-1188: Initialization of a Resource with an Insecure Default. Because the default behavior favored permissiveness over security, standard single-vector prompt injections easily bypassed the defense mechanism. This allowed attackers to interact directly with the LLM agents, overriding system instructions and exploiting integrated tools.
The root cause of CVE-2026-61439 resides in the threat calculation and decision logic of the InjectionDefense scanner in src/praisonai/praisonai/security/injection.py. The framework's defense engine executes several independent heuristic evaluations on each input. These heuristics check for indicators of prompt injection, such as instruction overrides, system role assumption, or data extraction patterns. If any heuristic is triggered, the engine calculates an overall threat level based on the number and severity of the triggered rules.
The scanner defines a hierarchical structure of risk levels, culminating in ThreatLevel.HIGH and ThreatLevel.CRITICAL. A ThreatLevel.HIGH classification is assigned to inputs that trigger a single, highly focused prompt injection vector. To reach the ThreatLevel.CRITICAL status, the incoming payload must typically trigger three or more independent detection heuristics simultaneously. This design assumption represents a critical flaw, as effective, highly focused prompt injection attacks rarely require or trigger multiple unrelated heuristics.
Because the default block_threshold was hardcoded to ThreatLevel.CRITICAL, the engine evaluated HIGH severity threats as non-blocking. The logical comparison (level >= ThreatLevel.CRITICAL) returned False for any single-vector attack classified as HIGH. As a result, the engine logged the high-threat warning but permitted the unblocked payload to continue through the pipeline, rendering the entire defense layer ineffective against targeted attacks.
The vulnerable code path is located within the scan_text function and the InjectionDefense class constructor. Prior to the patch, the scan_text function calculated whether an input should be blocked using an overly restrictive condition. Since the threshold was hardcoded to require a critical level, the framework failed to safeguard the downstream model against common single-pattern attacks.
Let us examine the vulnerable implementation of the scanning logic and constructor initialization in src/praisonai/praisonai/security/injection.py compared with the remediated codebase:
# VULNERABLE CODE (Versions < 4.6.78)
def scan_text(text: str, source: str = "external") -> ScanResult:
# ... evaluation logic ...
# Threat level is calculated based on triggered checks
level = ThreatLevel.HIGH # Triggered by standard prompt injection
# Insecure evaluation condition: only blocks CRITICAL (3+ checks)
blocked = (level >= ThreatLevel.CRITICAL) and not is_trusted
class InjectionDefense:
def __init__(
self,
extra_patterns: Optional[List[str]] = None,
block_threshold: ThreatLevel = ThreatLevel.CRITICAL, # Insecure default
trusted_sources: Optional[List[str]] = None,
):
self.block_threshold = block_thresholdTo resolve this defect, the maintainers modified the baseline threshold in commit 393de394087e3badc79acfec490323bcc99638bd. The condition was updated to use ThreatLevel.HIGH, ensuring single-vector attacks are intercepted.
# PATCHED CODE (Version 4.6.78+)
def scan_text(text: str, source: str = "external") -> ScanResult:
# ... evaluation logic ...
level = ThreatLevel.HIGH
# Patched evaluation condition: blocks both HIGH and CRITICAL threats
blocked = (level >= ThreatLevel.HIGH) and not is_trusted
class InjectionDefense:
def __init__(
self,
extra_patterns: Optional[List[str]] = None,
block_threshold: ThreatLevel = ThreatLevel.HIGH, # Secured default
trusted_sources: Optional[List[str]] = None,
):
self.block_threshold = block_thresholdThe remediation is structurally complete and eliminates the logical bypass for the default configuration. However, the framework's security still relies on the quality of its underlying regular expressions and pattern matchers. Security teams should recognize that while this patch enforces the intended security policy, it does not mitigate evasion techniques that bypass the heuristic signatures themselves.
Exploiting this vulnerability does not require complex binary payload development or memory corruption techniques. Instead, an attacker leverages the inherent parser logic of the underlying Large Language Model by submitting a crafted natural language prompt. Because the PraisonAI defense module evaluates threats on a per-rule basis, a single, clear command override only triggers a high-severity classification, bypassing the critical block threshold.
To execute the attack, an adversary must identify an input field, API endpoint, or chat interface routed to a vulnerable PraisonAI agent. The attacker then structures a prompt designed to override the agent's instructions, such as asking it to extract confidential data or execute administrative commands. Since the input matches only one specific heuristic category (such as instruction override), the framework permits the text to pass through, and the downstream LLM processes the payload as valid instructions.
The physical impact of this attack depends on the capabilities and integrations of the active agent. If the agent is equipped with file-system access, database connectivity, or external APIs, the attacker can hijack these tools. For instance, the attacker could command the agent to read local files, execute unauthorized database queries, or make outbound requests to malicious domains.
The impact of CVE-2026-61439 is assessed with a CVSS v3.1 base score of 7.5, reflecting high confidentiality implications. In LLM-driven applications, system instructions and contextual data often contain intellectual property, proprietary logic, or sensitive API keys. When an attacker successfully bypasses the input defense layer, they gain the ability to extract these details directly from the model's active context.
Furthermore, the vulnerability introduces potential integrity risks if the compromised agents are integrated with external tools. In multi-agent frameworks, agents are frequently granted capabilities to perform actions, such as sending emails, updating records, or executing code. By overriding system prompts, an unauthorized user can command the agent to execute these integrated actions, bypassing traditional access control layers.
From an operational perspective, the vulnerability is highly exploitable because the attack vector is network-based, requires no privileges, and demands zero user interaction. Organizations utilizing vulnerable versions of PraisonAI face immediate exposure if their agent interfaces are exposed to untrusted users or public networks. Although the security scanner successfully logs these high-severity events, the lack of active enforcement leaves the application vulnerable to automated exploitation.
The definitive remediation for CVE-2026-61439 is upgrading the PraisonAI framework to version 4.6.78 or higher. This upgrade shifts the default threshold of the InjectionDefense class to ThreatLevel.HIGH, ensuring that single-vector prompt injections are blocked automatically. Security teams should deploy this update across all environments, particularly where agents interact with external inputs.
For deployment environments where an immediate package upgrade is not feasible, organizations can implement a programmatic workaround. By explicitly setting the block_threshold parameter when instantiating the InjectionDefense component, developers can override the insecure default. The following code snippet demonstrates how to apply this mitigation manually:
from praisonai.security.injection import InjectionDefense, ThreatLevel
# Programmatic mitigation: Override default block threshold to HIGH
defense = InjectionDefense(block_threshold=ThreatLevel.HIGH)In addition to configuring the blocking threshold, organizations should establish robust detection and monitoring mechanisms. Security teams should configure alerting systems to parse application logs for warning indicators emitted by src/praisonai/praisonai/security/injection.py. Any warning indicating a ThreatLevel.HIGH detection that is not accompanied by a corresponding block action should be flagged as a high-priority security event.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
PraisonAI MervinPraison | < 4.6.78 | 4.6.78 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-1188 |
| Attack Vector | Network (AV:N) |
| CVSS v3.1 Score | 7.5 (High) |
| EPSS Score / Percentile | 0.00432 (0.43% probability) / 35.46th percentile |
| Impact | Confidentiality Breach / System Prompt Extraction |
| Exploit Status | Proof-of-Concept / Logical Bypass |
| CISA KEV Status | Not Listed |
The application configures a security resource (the InjectionDefense scanner threshold) with a default value that is too permissive.
CVE-2026-105642 is a critical remote code execution vulnerability in Ghost CMS, affecting versions 6.56.0 through 6.66.0. The flaw resides in how Ghost's backend handles external image metadata when generating 'Bookmark' cards in the post editor. When a low-privileged staff member inputs a malicious URL, the server fetches and processes an SVG containing an embedded payload, leading to command execution via the underlying, vulnerable image-processing component.
Kunstmaan CMS MediaBundle prior to version 7.3.2 contains a critical file upload vulnerability where case-sensitive extension checks can be bypassed using mixed-case file extensions. Because extension normalization occurs after the validation routine, files with mixed-case executable extensions (such as pHp) bypass checks but are stored with normalized lowercase executable extensions, allowing authenticated administrators to achieve remote code execution.
A critical remote code execution vulnerability was identified in WeasyPrint prior to version 70.0. When compiling HTML containing a malicious Encapsulated PostScript (EPS) graphic on a host with Ghostscript installed, Pillow invokes Ghostscript to process the image, executing arbitrary PostScript commands.
An authorization bypass vulnerability in the Spotify Backstage TechDocs backend plugin allows authenticated attackers with access to at least one valid TechDocs site to read arbitrary static documentation from other entities. This occurs due to un-sanitized relative subpaths passing directly to external storage drivers.
The @backstage/plugin-scaffolder-backend package prior to version 4.1.0 is vulnerable to sensitive information exposure in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user can retrieve backend-managed credentials, such as VCS access tokens and API keys, from affected task execution events and stored database logs. This vulnerability has been remediated in version 4.1.0 of the package and is bundled with the Backstage platform release v1.54.6.
A critical security flaw exists in PraisonAI before version 4.6.78 when operating in AgentMail webhook mode. The application processes incoming POST requests without checking for cryptographic signatures, allowing unauthenticated attackers to forge emails, spoof identities, and force AI agents to execute unauthorized operations.