CVE-2026-61439: Initialization of a Resource with an Insecure Default in MervinPraison PraisonAI
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.
AI Analysis
Technical Summary
CVE-2026-61439 describes a security vulnerability in MervinPraison's PraisonAI where the prompt injection defense mechanism is misconfigured. Specifically, the block threshold defaults to CRITICAL severity, meaning that prompt injection attacks classified as HIGH severity are not blocked but merely logged. This allows attackers to submit prompt injection attacks that trigger HIGH severity detection without being blocked, enabling unauthorized actions such as extracting system prompts and invoking tools without authorization. The vulnerability affects versions prior to 4.6.78, although no explicit affected versions were provided. The CVSS 4.0 base score is 8.7, indicating a high severity vulnerability with network attack vector, low attack complexity, no privileges or user interaction required, and high impact on confidentiality.
Potential Impact
Attackers can exploit this misconfiguration to bypass prompt injection defenses for HIGH severity attacks, potentially leading to unauthorized extraction of system prompts and unauthorized tool invocations. This could compromise the confidentiality and integrity of the system's operations. The vulnerability does not require privileges or user interaction and can be exploited remotely over the network.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch information is provided, users should monitor the vendor's communications for updates. Until a fix is available, consider adjusting the prompt injection defense configuration to lower the block threshold to include HIGH severity threats if possible, or implement additional detection and blocking mechanisms for prompt injection attacks.
CVE-2026-61439: Initialization of a Resource with an Insecure Default in MervinPraison PraisonAI
Description
PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.
CVSS v4.0
Score 8.7high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-61439 describes a security vulnerability in MervinPraison's PraisonAI where the prompt injection defense mechanism is misconfigured. Specifically, the block threshold defaults to CRITICAL severity, meaning that prompt injection attacks classified as HIGH severity are not blocked but merely logged. This allows attackers to submit prompt injection attacks that trigger HIGH severity detection without being blocked, enabling unauthorized actions such as extracting system prompts and invoking tools without authorization. The vulnerability affects versions prior to 4.6.78, although no explicit affected versions were provided. The CVSS 4.0 base score is 8.7, indicating a high severity vulnerability with network attack vector, low attack complexity, no privileges or user interaction required, and high impact on confidentiality.
Potential Impact
Attackers can exploit this misconfiguration to bypass prompt injection defenses for HIGH severity attacks, potentially leading to unauthorized extraction of system prompts and unauthorized tool invocations. This could compromise the confidentiality and integrity of the system's operations. The vulnerability does not require privileges or user interaction and can be exploited remotely over the network.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch information is provided, users should monitor the vendor's communications for updates. Until a fix is available, consider adjusting the prompt injection defense configuration to lower the block threshold to include HIGH severity threats if possible, or implement additional detection and blocking mechanisms for prompt injection attacks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-09T14:05:47.928Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a52461668715ace43df4a96
Added to database: 07/11/2026, 13:33:10 UTC
Last enriched: 07/18/2026, 15:11:59 UTC
Last updated: 08/23/2026, 22:52:12 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.