CVE-2026-61439: CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine
CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine Vulnerability ID: CVE-2026-61439 CVSS Score: 7.5 Published: 2026-10-07 This report provides a comprehensive technical analysis of
CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine
Vulnerability ID: CVE-2026-61439
CVSS Score: 7.5
Published: 2026-10-07
This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.
TL;DR
PraisonAI versions before 4.6.78 contain an insecure default configuration in the InjectionDefense component, allowing high-severity prompt injections to bypass active blocking controls.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-1188
- Attack Vector: Network (AV:N)
- CVSS v3.1 Score: 7.5 (High)
- EPSS Score / Percentile: 0.00432 (0.43% probability) / 35.46th percentile
- Impact: Confidentiality Breach / System Prompt Extraction
- Exploit Status: Proof-of-Concept / Logical Bypass
- CISA KEV Status: Not Listed
Affected Systems
- PraisonAI Framework
- PraisonAI Agents Module
-
PraisonAI: < 4.6.78 (Fixed in:
4.6.78)
Code Analysis
Commit: 393de39
Fix default block threshold in prompt injection defense to HIGH severity
diff --git a/src/praisonai/praisonai/security/injection.py b/src/praisonai/praisonai/security/injection.py
index 9d7f9a79cf..ce7acca988 100644
--- a/src/praisonai/praisonai/security/injection.py
+++ b/src/praisonai/praisonai/security/injection.py
@@ -233,7 +233,7 @@ def scan_text(text: str, source: str = "external") -> ScanResult:
level = ThreatLevel.CRITICAL
# Trusted sources are never blocked regardless of level
- blocked = (level >= ThreatLevel.CRITICAL) and not is_trusted
+ blocked = (level >= ThreatLevel.HIGH) and not is_trusted
if triggered:
logger.warning(
@@ -270,14 +270,14 @@ class InjectionDefense:
def __init__(
self,
extra_patterns: Optional[List[str]] = None,
- block_threshold: ThreatLevel = ThreatLevel.CRITICAL,
+ block_threshold: ThreatLevel = ThreatLevel.HIGH,
trusted_sources: Optional[List[str]] = None,
):
"""
Args:
extra_patterns: Additional regex patterns to include in Check 1.
block_threshold: Minimum threat level that causes blocking.
- Default: CRITICAL (only block if 3+ checks fire).
+ Default: HIGH (block single high-severity detections).
trusted_sources: Source names that bypass blocking.
"""
self._extra_patterns = extra_patterns or []
Mitigation Strategies
- Upgrade to PraisonAI version 4.6.78 or newer to apply the secure-by-default behavior.
- Manually configure the block_threshold parameter to ThreatLevel.HIGH when instantiating the InjectionDefense class.
- Implement real-time monitoring and alerting for ThreatLevel.HIGH logs that bypass active blocking in legacy installations.
Remediation Steps:
- Identify all microservices and deployments utilizing PraisonAI or praisonaiagents.
- Execute pip install --upgrade praisonai praisonaiagents to update the dependency to version 4.6.78 or higher.
- If immediate upgrading is impossible, edit application initialization code to enforce block_threshold=ThreatLevel.HIGH.
- Verify the configuration by executing a test query containing a single-vector prompt override and confirming it is blocked.
References
- GitHub Security Advisory GHSA-fj8f-m44g-c479
- VulnCheck Security Advisory
- Fix Commit (Git Repository Diff)
- NVD Vulnerability Detail
- Official CVE.org Record
Read the full report for CVE-2026-61439 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.