SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-61439

HIGH · CVSS 7.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-11 · Last synced 2026-08-10

CyberRota Analysis

AI-Generated

PraisonAI versions prior to 4.6.78 are vulnerable due to a misconfiguration in their prompt injection defense, which allows HIGH-severity threats to bypass security measures while only logging the incidents. This flaw enables attackers to execute single-vector prompt injection attacks, potentially leading to unauthorized access and manipulation of sensitive information. Organizations using affected versions should prioritize remediation to mitigate the risk of exploitation and protect their systems from potential breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61439
Severity
HIGH
CVSS
7.5
EPSS
0.26%

Original NVD Description

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.