Threat · curated 23 Jul 2026

NVD - CVE-2026-61439

Coverage timeline

23 Jul 2026nist.gov

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-61439 shows how a misconfigured default guardrail threshold in an AI agent framework can silently allow prompt injection attacks to extract system prompts and trigger unauthorized tool calls.

CVE-2026-61439 affects PraisonAI versions before 4.6.78, where a prompt injection defense misconfiguration defaults the block threshold to CRITICAL severity, letting HIGH-level threats pass unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation to achieve system prompt extraction and unauthorized tool invocations; VulnCheck rates it CVSS 8.7 HIGH and a fix is available in 4.6.78.