Praisonai · Praisonai · CVE-2026-61439
**Name of the Vulnerable Software and Affected Versions**
PraisonAI versions prior to 4.6.78
**Description**
A prompt injection defense misconfiguration exists where the block threshold defaults to CRITICAL severity. This allows threats categorized as HIGH severity to pass through without being blocked. Attackers can utilize single-vector prompt injection attacks, such as instruction overrides or financial manipulation, which trigger HIGH severity detection but are only logged. This flaw enables the extraction of system prompts and unauthorized tool invocations.
**Recommendations**
Update to version 4.6.78 or later.