<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 01:19:56 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-47391 — PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-47391</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MervinPraison PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI&amp;#39;s first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated attacker can send `message/send` to `/a2a`; the request reaches `agent.chat()`, and a real LLM can invoke the registered `calculate` tool. In testing with `gemini/gemini-2.5-flash-lite`, this resulted in arbitrary Python execution in the server process, confirmed by creation of a marker file from an unauthenticated HTTP request. The issue affects deployments following the official A2A example or similar unauthenticated public A2A deployments with unsafe tools. The default unauthenticated A2A surface also exposes task history and task cancellation APIs, increasing confidentiality and integrity impact. Version 4.6.40 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MervinPraison PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI&amp;#39;s first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated attacker can send `message/send` to `/a2a`; the request reaches `agent.chat()`, and a real LLM can invoke the registered `calculate` tool. In testing with `gemini/gemini-2.5-flash-lite`, this resulted in arbitrary Python execution in the server process, confirmed by creation of a marker file from an unauthenticated HTTP request. The issue affects deployments following the official A2A example or similar unauthenticated public A2A deployments with unsafe tools. The default unauthenticated A2A surface also exposes task history and task cancellation APIs, increasing confidentiality and integrity impact. Version 4.6.40 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-47391</guid>
    </item>
    <item>
      <title>GHSA-vg22-4gmj-prxw — PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vg22-4gmj-prxw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The first-party PraisonAI A2A server example combines three behaviors into a remotely exploitable Critical chain:&lt;/p&gt;
&lt;p&gt;1. The example exposes an A2A server without configuring `auth_token`.
2. The same example binds the server to `0.0.0.0`.
3. The example registers a `calculate(expression)` tool implemented with Python `eval(expression)`.&lt;/p&gt;
&lt;p&gt;An unauthenticated network client can send a JSON-RPC `message/send` request to `/a2a`. The A2A handler passes the attacker-controlled message to `agent.chat()`. With a real Gemini LLM (`gemini/gemini-2.5-flash-lite`), the model invoked the registered `calculate` tool, causing the example&amp;#39;s `eval()` call to execute Python in the server process. The canary wrote a marker file from an unauthenticated `/a2a` request.&lt;/p&gt;
&lt;p&gt;This is not a claim that every A2A deployment is automatically RCE. The Critical chain is confirmed for the first-party A2A example, and for deployments that follow the same pattern: public unauthenticated A2A plus an unsafe tool such as this `eval()`-based `calculate` tool. The default unauthenticated A2A surface is the remote entry point; the official example&amp;#39;s `eval()` tool provides the code execution sink.&lt;/p&gt;
&lt;p&gt;Earlier note:&lt;/p&gt;
&lt;p&gt;The unsafe official example existed earlier, but the complete unauthenticated `/a2a` `message/send` to `agent.chat()` exploit chain is only claimed here for versions where that endpoint is present and confirmed.&lt;/p&gt;
&lt;p&gt;## Trust Boundary&lt;/p&gt;
&lt;p&gt;The boundary that should be preserved is:&lt;/p&gt;
&lt;p&gt;```text
Unauthenticated…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The first-party PraisonAI A2A server example combines three behaviors into a remotely exploitable Critical chain:&lt;/p&gt;
&lt;p&gt;1. The example exposes an A2A server without configuring `auth_token`.
2. The same example binds the server to `0.0.0.0`.
3. The example registers a `calculate(expression)` tool implemented with Python `eval(expression)`.&lt;/p&gt;
&lt;p&gt;An unauthenticated network client can send a JSON-RPC `message/send` request to `/a2a`. The A2A handler passes the attacker-controlled message to `agent.chat()`. With a real Gemini LLM (`gemini/gemini-2.5-flash-lite`), the model invoked the registered `calculate` tool, causing the example&amp;#39;s `eval()` call to execute Python in the server process. The canary wrote a marker file from an unauthenticated `/a2a` request.&lt;/p&gt;
&lt;p&gt;This is not a claim that every A2A deployment is automatically RCE. The Critical chain is confirmed for the first-party A2A example, and for deployments that follow the same pattern: public unauthenticated A2A plus an unsafe tool such as this `eval()`-based `calculate` tool. The default unauthenticated A2A surface is the remote entry point; the official example&amp;#39;s `eval()` tool provides the code execution sink.&lt;/p&gt;
&lt;p&gt;Earlier note:&lt;/p&gt;
&lt;p&gt;The unsafe official example existed earlier, but the complete unauthenticated `/a2a` `message/send` to `agent.chat()` exploit chain is only claimed here for versions where that endpoint is present and confirmed.&lt;/p&gt;
&lt;p&gt;## Trust Boundary&lt;/p&gt;
&lt;p&gt;The boundary that should be preserved is:&lt;/p&gt;
&lt;p&gt;```text
Unauthenticated…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vg22-4gmj-prxw</guid>
    </item>
  </channel>
</rss>
