<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 20:30:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280513</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280513</link>
      <description>EUVD-2026-280513</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280513</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34939</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34939</link>
      <description>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a complete service outage. This issue has been patched in version 4.5.90.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a complete service outage. This issue has been patched in version 4.5.90.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34939</guid>
    </item>
    <item>
      <title>GHSA-8w9j-hc3g-3g7f — PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8w9j-hc3g-3g7f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`MCPToolIndex.search_tools()` compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the `re` engine, blocking the Python thread for hundreds of seconds and causing a complete service outage.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`tool_index.py:365` (source) -&amp;gt; `tool_index.py:368` (sink)
```python
# source -- query taken directly from caller, no validation
def search_tools(self, query: str) -&amp;gt; List[ToolInfo]:
    import re&lt;/p&gt;
&lt;p&gt;# sink -- compiled and applied with no timeout or exception handling
    pattern = re.compile(query, re.IGNORECASE)
    for tool in self.get_all_tools():
        if pattern.search(tool.name) or pattern.search(tool.hint):
            matches.append(tool)
```&lt;/p&gt;
&lt;p&gt;### PoC
```python
# tested on: praisonai==1.5.87 (source install)
# install: pip install -e src/praisonai
import sys, time, json
sys.path.insert(0, &amp;#39;src/praisonai&amp;#39;)
from pathlib import Path&lt;/p&gt;
&lt;p&gt;mcp_dir = Path.home() / &amp;#39;.praison&amp;#39; / &amp;#39;mcp&amp;#39; / &amp;#39;servers&amp;#39; / &amp;#39;test_server&amp;#39;
mcp_dir.mkdir(parents=True, exist_ok=True)
(mcp_dir / &amp;#39;_index.json&amp;#39;).write_text(json.dumps([
    {&amp;#34;name&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;hint&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;}
]))
(mcp_dir / &amp;#39;_status.json&amp;#39;).write_text(json.dumps({
    &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;, &amp;#34;available&amp;#34;: True, &amp;#34;auth_required&amp;#34;: False,
    &amp;#34;last_sync&amp;#34;: time.time(), &amp;#34;tool_count&amp;#34;: 1, &amp;#34;error&amp;#34;: None
}))&lt;/p&gt;
&lt;p&gt;from praisonai.mcp_server.tool_index import MCPToolIndex
index = MCPToolIndex()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`MCPToolIndex.search_tools()` compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the `re` engine, blocking the Python thread for hundreds of seconds and causing a complete service outage.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`tool_index.py:365` (source) -&amp;gt; `tool_index.py:368` (sink)
```python
# source -- query taken directly from caller, no validation
def search_tools(self, query: str) -&amp;gt; List[ToolInfo]:
    import re&lt;/p&gt;
&lt;p&gt;# sink -- compiled and applied with no timeout or exception handling
    pattern = re.compile(query, re.IGNORECASE)
    for tool in self.get_all_tools():
        if pattern.search(tool.name) or pattern.search(tool.hint):
            matches.append(tool)
```&lt;/p&gt;
&lt;p&gt;### PoC
```python
# tested on: praisonai==1.5.87 (source install)
# install: pip install -e src/praisonai
import sys, time, json
sys.path.insert(0, &amp;#39;src/praisonai&amp;#39;)
from pathlib import Path&lt;/p&gt;
&lt;p&gt;mcp_dir = Path.home() / &amp;#39;.praison&amp;#39; / &amp;#39;mcp&amp;#39; / &amp;#39;servers&amp;#39; / &amp;#39;test_server&amp;#39;
mcp_dir.mkdir(parents=True, exist_ok=True)
(mcp_dir / &amp;#39;_index.json&amp;#39;).write_text(json.dumps([
    {&amp;#34;name&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;hint&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;}
]))
(mcp_dir / &amp;#39;_status.json&amp;#39;).write_text(json.dumps({
    &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;, &amp;#34;available&amp;#34;: True, &amp;#34;auth_required&amp;#34;: False,
    &amp;#34;last_sync&amp;#34;: time.time(), &amp;#34;tool_count&amp;#34;: 1, &amp;#34;error&amp;#34;: None
}))&lt;/p&gt;
&lt;p&gt;from praisonai.mcp_server.tool_index import MCPToolIndex
index = MCPToolIndex()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8w9j-hc3g-3g7f</guid>
    </item>
    <item>
      <title>PYSEC-2026-2907 — PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2907</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`MCPToolIndex.search_tools()` compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the `re` engine, blocking the Python thread for hundreds of seconds and causing a complete service outage.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`tool_index.py:365` (source) -&amp;gt; `tool_index.py:368` (sink)
```python
# source -- query taken directly from caller, no validation
def search_tools(self, query: str) -&amp;gt; List[ToolInfo]:
    import re&lt;/p&gt;
&lt;p&gt;# sink -- compiled and applied with no timeout or exception handling
    pattern = re.compile(query, re.IGNORECASE)
    for tool in self.get_all_tools():
        if pattern.search(tool.name) or pattern.search(tool.hint):
            matches.append(tool)
```&lt;/p&gt;
&lt;p&gt;### PoC
```python
# tested on: praisonai==1.5.87 (source install)
# install: pip install -e src/praisonai
import sys, time, json
sys.path.insert(0, &amp;#39;src/praisonai&amp;#39;)
from pathlib import Path&lt;/p&gt;
&lt;p&gt;mcp_dir = Path.home() / &amp;#39;.praison&amp;#39; / &amp;#39;mcp&amp;#39; / &amp;#39;servers&amp;#39; / &amp;#39;test_server&amp;#39;
mcp_dir.mkdir(parents=True, exist_ok=True)
(mcp_dir / &amp;#39;_index.json&amp;#39;).write_text(json.dumps([
    {&amp;#34;name&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;hint&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;}
]))
(mcp_dir / &amp;#39;_status.json&amp;#39;).write_text(json.dumps({
    &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;, &amp;#34;available&amp;#34;: True, &amp;#34;auth_required&amp;#34;: False,
    &amp;#34;last_sync&amp;#34;: time.time(), &amp;#34;tool_count&amp;#34;: 1, &amp;#34;error&amp;#34;: None
}))&lt;/p&gt;
&lt;p&gt;from praisonai.mcp_server.tool_index import MCPToolIndex
index = MCPToolIndex()…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`MCPToolIndex.search_tools()` compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the `re` engine, blocking the Python thread for hundreds of seconds and causing a complete service outage.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`tool_index.py:365` (source) -&amp;gt; `tool_index.py:368` (sink)
```python
# source -- query taken directly from caller, no validation
def search_tools(self, query: str) -&amp;gt; List[ToolInfo]:
    import re&lt;/p&gt;
&lt;p&gt;# sink -- compiled and applied with no timeout or exception handling
    pattern = re.compile(query, re.IGNORECASE)
    for tool in self.get_all_tools():
        if pattern.search(tool.name) or pattern.search(tool.hint):
            matches.append(tool)
```&lt;/p&gt;
&lt;p&gt;### PoC
```python
# tested on: praisonai==1.5.87 (source install)
# install: pip install -e src/praisonai
import sys, time, json
sys.path.insert(0, &amp;#39;src/praisonai&amp;#39;)
from pathlib import Path&lt;/p&gt;
&lt;p&gt;mcp_dir = Path.home() / &amp;#39;.praison&amp;#39; / &amp;#39;mcp&amp;#39; / &amp;#39;servers&amp;#39; / &amp;#39;test_server&amp;#39;
mcp_dir.mkdir(parents=True, exist_ok=True)
(mcp_dir / &amp;#39;_index.json&amp;#39;).write_text(json.dumps([
    {&amp;#34;name&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;hint&amp;#34;: &amp;#34;a&amp;#34; * 30 + &amp;#34;!&amp;#34;, &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;}
]))
(mcp_dir / &amp;#39;_status.json&amp;#39;).write_text(json.dumps({
    &amp;#34;server&amp;#34;: &amp;#34;test_server&amp;#34;, &amp;#34;available&amp;#34;: True, &amp;#34;auth_required&amp;#34;: False,
    &amp;#34;last_sync&amp;#34;: time.time(), &amp;#34;tool_count&amp;#34;: 1, &amp;#34;error&amp;#34;: None
}))&lt;/p&gt;
&lt;p&gt;from praisonai.mcp_server.tool_index import MCPToolIndex
index = MCPToolIndex()…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2907</guid>
    </item>
  </channel>
</rss>
