# CVE-2026-61439: CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine

> Source: <https://dev.to/cverports/cve-2026-61439-cve-2026-61439-prompt-injection-defense-bypass-in-praisonai-injectiondefense-engine-k0p>
> Published: 2026-10-07 21:31:01+00:00

# 
  
  
  CVE-2026-61439: Prompt Injection Defense Bypass in PraisonAI InjectionDefense Engine

**Vulnerability ID:** CVE-2026-61439

**CVSS Score:** 7.5

**Published:** 2026-10-07

This report provides a comprehensive technical analysis of CVE-2026-61439 (GHSA-fj8f-m44g-c479), a prompt injection defense bypass vulnerability in the PraisonAI multi-agent framework. In versions prior to 4.6.78, the InjectionDefense scanner threshold defaulted to CRITICAL. This allowed single-vector prompt injections classified as HIGH severity (e.g., direct instruction overrides or financial manipulations) to pass through unblocked, enabling attackers to extract system prompts and execute unauthorized agent tools.

## 
  
  
  TL;DR

PraisonAI versions before 4.6.78 contain an insecure default configuration in the InjectionDefense component, allowing high-severity prompt injections to bypass active blocking controls.

### 
  
  
  ⚠️ Exploit Status: POC

## 
  
  
  Technical Details

- 
**CWE ID** : CWE-1188
- 
**Attack Vector** : Network (AV:N)
- 
**CVSS v3.1 Score** : 7.5 (High)
- 
**EPSS Score / Percentile** : 0.00432 (0.43% probability) / 35.46th percentile
- 
**Impact** : Confidentiality Breach / System Prompt Extraction
- 
**Exploit Status** : Proof-of-Concept / Logical Bypass
- 
**CISA KEV Status** : Not Listed

## 
  
  
  Affected Systems

- PraisonAI Framework
- PraisonAI Agents Module
- 
**PraisonAI** : < 4.6.78 (Fixed in:`4.6.78` )

## 
  
  
  Code Analysis

Fix default block threshold in prompt injection defense to HIGH severity

## 
  
  
  Mitigation Strategies

- Upgrade to PraisonAI version 4.6.78 or newer to apply the secure-by-default behavior.
- Manually configure the block_threshold parameter to ThreatLevel.HIGH when instantiating the InjectionDefense class.
- Implement real-time monitoring and alerting for ThreatLevel.HIGH logs that bypass active blocking in legacy installations.

**Remediation Steps:**

1. Identify all microservices and deployments utilizing PraisonAI or praisonaiagents.
2. Execute pip install --upgrade praisonai praisonaiagents to update the dependency to version 4.6.78 or higher.
3. If immediate upgrading is impossible, edit application initialization code to enforce block_threshold=ThreatLevel.HIGH.
4. Verify the configuration by executing a test query containing a single-vector prompt override and confirming it is blocked.

## 
  
  
  References

*[Read the full report for CVE-2026-61439 on our website](https://cvereports.com/reports/CVE-2026-61439) for more details including interactive diagrams and full exploit analysis.*
