{"slug": "cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai", "title": "CVE-2026-61439: CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine", "summary": "PraisonAI versions before 4.6.78 shipped with an insecure default in its InjectionDefense component, where the block threshold defaulted to CRITICAL and allowed single-vector prompt injections rated HIGH — such as direct instruction overrides and financial manipulations — to pass unblocked, according to CVE-2026-61439 (CVSS 7.5). The flaw, tracked as CWE-1188 and rated network-exploitable with a proof-of-concept, could let attackers extract system prompts and invoke unauthorized agent tools. The fix in 4.6.78 lowers the default block threshold to HIGH severity, and users who cannot upgrade immediately can set block_threshold=ThreatLevel.HIGH manually.", "body_md": "# \n  \n  \n  CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine\n\n**Vulnerability ID:** CVE-2026-61439\n\n**CVSS Score:** 7.5\n\n**Published:** 2026-10-07\n\nThis report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.\n\n## \n  \n  \n  TL;DR\n\nPraisonAI versions before 4.6.78 contain an insecure default configuration in the InjectionDefense component, allowing high-severity prompt injections to bypass active blocking controls.\n\n### \n  \n  \n  ⚠️ Exploit Status: POC\n\n## \n  \n  \n  Technical Details\n\n- \n**CWE ID** : CWE-1188\n- \n**Attack Vector** : Network (AV:N)\n- \n**CVSS v3.1 Score** : 7.5 (High)\n- \n**EPSS Score / Percentile** : 0.00432 (0.43% probability) / 35.46th percentile\n- \n**Impact** : Confidentiality Breach / System Prompt Extraction\n- \n**Exploit Status** : Proof-of-Concept / Logical Bypass\n- \n**CISA KEV Status** : Not Listed\n\n## \n  \n  \n  Affected Systems\n\n- PraisonAI Framework\n- PraisonAI Agents Module\n- \n**PraisonAI** : < 4.6.78 (Fixed in:`4.6.78` )\n\n## \n  \n  \n  Code Analysis\n\nFix default block threshold in prompt injection defense to HIGH severity\n\n## \n  \n  \n  Mitigation Strategies\n\n- Upgrade to PraisonAI version 4.6.78 or newer to apply the secure-by-default behavior.\n- Manually configure the block_threshold parameter to ThreatLevel.HIGH when instantiating the InjectionDefense class.\n- Implement real-time monitoring and alerting for ThreatLevel.HIGH logs that bypass active blocking in legacy installations.\n\n**Remediation Steps:**\n\n1. Identify all microservices and deployments utilizing PraisonAI or praisonaiagents.\n2. Execute pip install --upgrade praisonai praisonaiagents to update the dependency to version 4.6.78 or higher.\n3. If immediate upgrading is impossible, edit application initialization code to enforce block_threshold=ThreatLevel.HIGH.\n4. Verify the configuration by executing a test query containing a single-vector prompt override and confirming it is blocked.\n\n## \n  \n  \n  References\n\n*[Read the full report for CVE-2026-61439 on our website](https://cvereports.com/reports/CVE-2026-61439) for more details including interactive diagrams and full exploit analysis.*", "url": "https://wpnews.pro/news/cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai", "canonical_source": "https://dev.to/cverports/cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai-injectiondefense-engine-k0p", "published_at": "2026-10-07 21:31:01+00:00", "updated_at": "2026-10-07 21:46:56.452848+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-tools", "developer-tools"], "entities": ["PraisonAI", "InjectionDefense", "CVE-2026-61439", "praisonaiagents"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai", "markdown": "https://wpnews.pro/news/cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai.md", "text": "https://wpnews.pro/news/cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai.txt", "jsonld": "https://wpnews.pro/news/cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai.jsonld"}}