← العودة للجدول
CVE-2026-47391
CVE-2026-47391 — GHSA: PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
📅 2026-05-29
🔴 Critical 🔥 No GHSA Data Breach Linux CVSS 9.8

📋 الوصف الكامل

## Summary The first-party PraisonAI A2A server example combines three behaviors into a remotely exploitable Critical chain: 1. The example exposes an A2A server without configuring `auth_token`. 2. The same example binds the server to `0.0.0.0`. 3. The example registers a `calculate(expression)` tool implemented with Python `eval(expression)`. An unauthenticated network client can send a JSON-

💻 الأنظمة المتأثرة

GHSA: PraisonAI's unauthenticated

⚠️ نوع التهديد

Data Breach

🔗 CVE ID

CVE-2026-47391

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←