CVE-2026-61439: CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine

# security# cve# cybersecurity
CVE-2026-61439: CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense EngineCVE Reports

CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense...

CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine

Vulnerability ID: CVE-2026-61439
CVSS Score: 7.5
Published: 2026-10-07

This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.

TL;DR

PraisonAI versions before 4.6.78 contain an insecure default configuration in the InjectionDefense component, allowing high-severity prompt injections to bypass active blocking controls.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1188
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Score: 7.5 (High)
  • EPSS Score / Percentile: 0.00432 (0.43% probability) / 35.46th percentile
  • Impact: Confidentiality Breach / System Prompt Extraction
  • Exploit Status: Proof-of-Concept / Logical Bypass
  • CISA KEV Status: Not Listed

Affected Systems

  • PraisonAI Framework
  • PraisonAI Agents Module
  • PraisonAI: < 4.6.78 (Fixed in: 4.6.78)

Code Analysis

Commit: 393de39

Fix default block threshold in prompt injection defense to HIGH severity

diff --git a/src/praisonai/praisonai/security/injection.py b/src/praisonai/praisonai/security/injection.py
index 9d7f9a79cf..ce7acca988 100644
--- a/src/praisonai/praisonai/security/injection.py
+++ b/src/praisonai/praisonai/security/injection.py
@@ -233,7 +233,7 @@ def scan_text(text: str, source: str = "external") -> ScanResult:
         level = ThreatLevel.CRITICAL

     # Trusted sources are never blocked regardless of level
-    blocked = (level >= ThreatLevel.CRITICAL) and not is_trusted
+    blocked = (level >= ThreatLevel.HIGH) and not is_trusted

     if triggered:
         logger.warning(
@@ -270,14 +270,14 @@ class InjectionDefense:
     def __init__(
         self,
         extra_patterns: Optional[List[str]] = None,
-        block_threshold: ThreatLevel = ThreatLevel.CRITICAL,
+        block_threshold: ThreatLevel = ThreatLevel.HIGH,
         trusted_sources: Optional[List[str]] = None,
     ):
         """
         Args:
             extra_patterns: Additional regex patterns to include in Check 1.
             block_threshold: Minimum threat level that causes blocking.
-                             Default: CRITICAL (only block if 3+ checks fire).
+                             Default: HIGH (block single high-severity detections).
              trusted_sources: Source names that bypass blocking.
         """
         self._extra_patterns = extra_patterns or []
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade to PraisonAI version 4.6.78 or newer to apply the secure-by-default behavior.
  • Manually configure the block_threshold parameter to ThreatLevel.HIGH when instantiating the InjectionDefense class.
  • Implement real-time monitoring and alerting for ThreatLevel.HIGH logs that bypass active blocking in legacy installations.

Remediation Steps:

  1. Identify all microservices and deployments utilizing PraisonAI or praisonaiagents.
  2. Execute pip install --upgrade praisonai praisonaiagents to update the dependency to version 4.6.78 or higher.
  3. If immediate upgrading is impossible, edit application initialization code to enforce block_threshold=ThreatLevel.HIGH.
  4. Verify the configuration by executing a test query containing a single-vector prompt override and confirming it is blocked.

References


Read the full report for CVE-2026-61439 on our website for more details including interactive diagrams and full exploit analysis.