chiprook
← Security
SecurityOctober 8, 2026, 04:31

CVE-2026-61439: Prompt injection defense bypass in PraisonAI

PraisonAI versions before 4.6.78 shipped with the InjectionDefense block threshold defaulting to CRITICAL, letting single-vector HIGH-severity prompt injections through. The flaw, tracked as CVE-2026-61439 with a CVSS score of 7.5, allows system prompt extraction and unauthorized agent tool execution; it is fixed in 4.6.78.

CVE-2026-61439: Prompt injection defense bypass in PraisonAI
#PraisonAI
Read next
Security

OpenAPA brings deterministic prompt-injection defense to AI agents

Security

CVE-2026-41264: A Regex Let Prompts Run Code in Flowise

Security

CVE-2026-65660: SharePoint code injection reachable by low-privilege user

Security

CVE-2026-67401: cPanel EmailTrack SQL Injection Leads to Root Takeover