CVE-2026-61439: CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine
CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine Vulnerability ID: CVE-2026-61439 CVSS Score: 7.5 Published: 2026-10-07 This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools. TL;DR PraisonAI versions before 4.6.78 contain an insecure default configuration in the InjectionDefense component, allowing high-severity prompt injections to bypass active blocking controls. ⚠️ Exploit Status: POC Technical Details CWE ID: CWE-1188 Attack Vector: Network (AV:N) CVSS v3.1 Score: 7.5 (High) EPSS Score / Percentile: 0.00432 (0.43% probability) / 35.46th percentile Impact: Confidentiality Breach / System Prompt Extraction Exploit Status: Proof-of-Concept / Logical Bypass CISA KEV Status: Not Listed Affected Systems PraisonAI Framework PraisonAI Agents Module PraisonAI: < 4.6.78 (Fixed in: 4.6.78) Code Analysis Commit: 393de39 Fix default block threshold in prompt injection defense to HIGH severity diff —git a/src/praisonai/praisonai/security/injection.py b/src/praisonai/praisonai/security/injection.py index 9d7f9a79cf..ce7acca988 100644 --- a/src/praisonai/praisonai/security/injection.py +++ b/src/praisonai/praisonai/security/injection.py @@ -233,7 +233,7 @@ def scan_text(text: str, source: str = “external”) -> ScanResult: level = ThreatLevel.CRITICAL # Trusted sources are never blocked regardless of level - blocked = (level >= ThreatLevel.CRITICAL) and not is_trusted + blocked = (level >= ThreatLevel.HIGH) and not is_trusted if triggered: logger.warning( @@ -270,14 +270,14 @@ class InjectionDefense: def init( self, extra_patterns: Optional[List[str]] = None, - block_threshold: ThreatLevel = ThreatLevel.CRITICAL, + block_threshold: ThreatLevel = ThreatLevel.HIGH, trusted_sources: Optional[List[str]] = None, ): """ Args: extra_patterns: Additional regex patterns to include in Check 1. block_threshold: Minimum threat level that causes blocking. - Default: CRITICAL (only block if 3+ checks fire). + Default: HIGH (block single high-severity detections). trusted_sources: Source names that bypass blocking. """ self._extra_patterns = extra_patterns or [] Mitigation Strategies Upgrade to PraisonAI version 4.6.78 or newer to apply the secure-by-default behavior. Manually configure the block_threshold parameter to ThreatLevel.HIGH when instantiating the InjectionDefense class. Implement real-time monitoring and alerting for ThreatLevel.HIGH logs that bypass active blocking in legacy installations. Remediation Steps: Identify all microservices and deployments utilizing PraisonAI or praisonaiagents. Execute pip install —upgrade praisonai praisonaiagents to update the dependency to version 4.6.78 or higher. If immediate upgrading is impossible, edit application initialization code to enforce block_threshold=ThreatLevel.HIGH. Verify the configuration by executing a test query containing a single-vector prompt override and confirming it is blocked. References GitHub Security Advisory GHSA-fj8f-m44g-c479 VulnCheck Security Advisory Fix Commit (Git Repository Diff) NVD Vulnerability Detail Official CVE.org Record Read the full report for CVE-2026-61439 on our website for more details including interactive diagrams and full exploit analysis.