CVE-2026-39890Disclosure(praison / praisonai)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch praison praisonai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an attacker to craft a malicious YAML file that, when parsed, executes arbitrary JavaScript code. An attacker can exploit this vulnerability by uploading a malicious agent definition file via the API endpoint, leading to remote code execution (RCE) on the server. This vulnerability is fixed in 4.5.115.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-08); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-09: 2Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-09: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-08: 2Technical Details · 2026-04-09: 2Technical Details · 2026-04-15: 104-0804-0904-15
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure2
2026-04-092
Disclosure1Patch1
2026-04-151
Disclosure1
Full discourse5 posts
  • RB@RynBsd
    Disclosure

    CVE-2026-39888 + CVE-2026-39890: RCE حرج بدرجة 9.9 في منصة PraisonAI متعددة الوكلاء https://t.co/ZEhcbpN0Ep

    Post summary

    A tweet announces two CVEs (CVE-2026-39888 and CVE-2026-39890) as critical remote code execution vulnerabilities on the PraisonAI multi‑agent platform, with a severity score of 9.9, and provides no PoC, exploit, or patch details.

    0000031
    8 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39890: CRITICAL] Beware of cyber threats! Prior to version 4.5.115, a vulnerability in PrasionAI can allow attackers to execute JavaScript code via malicious YAML files. Update to version 4.5.115 t...#cve,CVE-2026-39890,#cybersecurity https://cvefind.com/CVE-2026-39890

    Post summary

    The tweet alerts users to a critical JavaScript execution vulnerability in PrasionAI, emphasizing the need to update to version 4.5.115.

    0000030
    619 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `PraisonAI` is vulnerable to RCE (CVE-2026-39890) via insecure YAML deserialization in agent definition loading. Review configurations. #RCE #Deserialization #AppSec https://www.pulsepatch.io/posts/cve-2026-39890-praisonai-rce-yaml-deserialization

    Post summary

    This tweet announces a critical RCE in PraisonAI caused by insecure YAML deserialization (CVE‑2026‑39890) and links to a PulsePatch article for more details.

    0000057
    11 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39890 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling da… https://www.cve.org/CVERecord?id=CVE-2026-39890 ----- Traducción: CVE-2026-39890 Pra… http://infoflow.cloud`

    Post summary

    The post announces a vulnerability in PraisonAI’s AgentService.loadAgentFromFile, noting insecure YAML parsing in versions prior to 4.5.115, but provides no PoC, exploit code, or patch details.

    0000024
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39890 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling da… https://www.cve.org/CVERecord?id=CVE-2026-39890

    Post summary

    The text discloses that PraisonAI versions before 4.5.115 are vulnerable due to insecure js‑yaml parsing in AgentService.loadAgentFromFile, without mentioning PoC, exploitation, or patch information.

    00000186
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more