SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-60086

MEDIUM · CVSS 5.3 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

PraisonAI versions prior to 4.6.78 are vulnerable to a prompt injection defense bypass, allowing attackers to exploit single or double-vector prompt injections classified as HIGH threat level. This vulnerability can enable unauthorized access to the model, potentially compromising its integrity and functionality. Organizations using affected versions should prioritize updating to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-60086
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%

Original NVD Description

PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat level and pass through unblocked to reach the model.