Column 1
Skip to content
Column 1

July 10 AI and Dev Tool CVE Radar: PraisonAI, Crawl4AI, Vikunja

July 10 CVE radar checklist for PraisonAI Crawl4AI Vikunja Capgo Lucee and FlaskBB patching

Radar window: July 10, 2026, 14:00-16:00 UTC. NVD added a new group of critical and high CVEs affecting self-hosted AI tools, developer utilities, project-management software, app update infrastructure, CFML servers, and forum software.

This is not a WordPress plugin batch like the earlier July 10 pass. The reader action is for hosting admins, internal IT teams, SaaS operators, and developers who have been testing AI agents or self-hosted tools on public VPS, Docker, staging, or customer support infrastructure.

CISA KEV did not add new entries during this pass. The publish-worthy change came from the post-14:00 UTC NVD high and critical publication window, with GitHub Security Advisory and vendor-adjacent references for several affected projects.

Highest Priority Checks

Product CVE Severity What admins should do
Vikunja CVE-2026-56765 Critical, 9.8 Update to 2.2.1 or newer. Review shared links, project access, and attachment history on exposed self-hosted instances.
PraisonAI CVE-2026-61444 Critical, 9.1 Update to 4.6.78 or newer. Restrict public access to AI job and deployment services until patched and reviewed.
Crawl4AI CVE-2026-56261 High, 8.6 Update to 0.8.7 or newer. Block AI crawler services from reaching internal-only networks, cloud metadata, and private service ranges.
PraisonAI and praisonaiagents CVE-2026-60091, CVE-2026-61434, CVE-2026-61437 High, 7.2-8.8 Patch PraisonAI to 4.6.78 or newer and praisonaiagents to 1.6.78 or newer. Audit workflows, job history, and service credentials.
Capgo / capacitor-updater CVE-2026-56254, CVE-2026-56279, CVE-2026-56305 High, 7.0-8.3 Update to 12.128.2 or newer. Review update distribution trust, organization membership, account sessions, and billing/admin access.
Lucee CFML Server CVE-2026-29519 High, 8.2 Check the active Lucee release line and apply the vendor-fixed build for that branch. Keep admin surfaces behind VPN or trusted access while patching.
FlaskBB CVE-2026-22659 High, 8.1 Patch to a fixed release or vendor commit when available. Review moderator accounts and recent topic moderation actions.

Why This Matters For Hosting Teams

AI and developer tools are often installed quickly for experiments, demos, support automation, or internal workflow testing. That creates an exposure problem: these services may have broad file, network, model, workflow, or application credentials even when they were never meant to be internet-facing.

The safer response is to treat this batch as an inventory check. Search for PraisonAI, Crawl4AI, Vikunja, Capgo, Lucee, and FlaskBB across VPS, Docker hosts, staging servers, customer portals, and developer workstations. Patch first, then restrict access so only trusted users and networks can reach the service.

Backup-First Response

Before changing production systems, take a fresh backup or VM snapshot. For self-hosted apps, include the database, uploaded files, configuration, secrets inventory, and container or package version state. For app update systems, preserve enough audit data to understand what update packages, users, and organizations were active before maintenance.

After patching, rotate service tokens if exposure cannot be ruled out, review recent administrative sessions, check for new users or unexpected workflow changes, and verify that the application still works from a clean browser session. For AI or crawler tools, also confirm that outbound access to internal-only addresses is blocked by network policy, not just by application settings.

Safe Exposure Reduction

  • Move AI job runners, crawlers, and agent dashboards behind VPN, SSO, or a private network.
  • Block application containers from reaching cloud metadata and internal control-plane services unless explicitly required.
  • Separate experimental AI tools from customer production data, billing systems, backup systems, and hosting control panels.
  • Review app updater pipelines for signing, release, and organization-access assumptions.
  • Keep CFML and forum admin areas behind trusted access, especially during maintenance windows.

How FixItPhill Is Tracking This Pass

This post is based on the July 10 NVD high/critical publication window from 14:00-16:00 UTC, GitHub Security Advisory references where available, the CISA KEV comparison against the previous pass, and public FixItPhill duplicate searches. No active exploitation was confirmed during this pass, but the severity and exposure profile make these worth handling before normal monthly maintenance.

Related defensive reading: Gitea Docker reverse proxy auth patch checklist, July 10 WordPress CVE radar, and how to back up WordPress in cPanel and WHM.

Sources

July 11 update: new PraisonAI critical and high CVEs

Update: NVD published a new July 11 cluster for PraisonAI after the original July 10 radar article went live. This changes the priority for teams running PraisonAI agents, AI coding helpers, browser/crawl tooling, AgentMail workflows, platform workspaces, or Capgo deployments near app-server or automation environments.

This update stays defensive. It summarizes the affected component families, fixed-version targets, and safe checks without publishing abuse-ready request details, proof steps, or scanner-ready material.

Critical records to handle first

  • CVE-2026-61447 - CVSS 10.0: PraisonAI code-agent execution risk before the fixed 1.6.78 line.
  • CVE-2026-61445 - CVSS 9.9: PraisonAI AICoder file-write and command-execution risk before 4.6.78.
  • CVE-2026-60090 - CVSS 9.8: PraisonAI knowledge-store collection validation risk before 4.6.78.

High-severity records to include in the same maintenance window

  • CVE-2026-61426 - CVSS 8.6: PraisonAI insecure default exposure before 1.7.3.
  • CVE-2026-61429 - CVSS 8.5: PraisonAI crawl/browser internal-resource exposure before 1.6.78.
  • CVE-2026-61439 - CVSS 7.5: PraisonAI prompt-injection defense threshold issue before 4.6.78.
  • CVE-2026-61428 - CVSS 7.3: PraisonAI AgentMail message-validation issue before 4.6.78.
  • CVE-2026-61442 - CVSS 7.1: PraisonAI Platform authorization issue before 0.1.9.
  • CVE-2026-56303 - CVSS 7.5: Capgo credential-metadata disclosure risk before 12.128.2.

Admin action checklist

  • Inventory PraisonAI, PraisonAI agent, PraisonAI platform, AgentMail, browser/crawl, code-agent, and Capgo deployments across production, staging, demos, notebooks, and developer hosts.
  • Update affected components to the fixed version named by the relevant advisory. For this cluster, fixed targets include 4.6.78 or newer, 1.6.78 or newer, 1.7.3 or newer, praisonai-platform 0.1.9 or newer, and Capgo 12.128.2 or newer depending on what is installed.
  • Keep agent UIs, automation services, chat interfaces, browser/crawl workers, and development dashboards behind authentication, VPN, or an internal network boundary. Do not leave demo services exposed.
  • Review recent agent runs, file changes, database changes, outbound network activity, mailbox activity, project edits, and automation logs for unexpected behavior.
  • Rotate API keys, LLM provider keys, mail tokens, database credentials, and environment values if any affected service was exposed or ran with broad permissions.
  • Reduce filesystem and shell permissions for AI coding helpers and agent workers. Treat them as untrusted automation until patched and isolated.
  • For hosting providers and agencies, notify customers only with defensive guidance: update versions, restrict exposure, review logs, rotate credentials when needed, and confirm service isolation.

Source records

FixItPhill will continue tracking whether any of these records are added to CISA KEV or receive confirmed active-exploitation reporting. As of this update, the immediate action is to patch, restrict exposure, review logs, and rotate sensitive values where exposure is possible.