
🔴 PraisonAI, Template Injection, #CVE-2026-39891 (High) https://dailycve.com/praisonai-template-injection-cve-2026-39891-high/
Post summary
The post announces a new high‑severity template injection vulnerability in PraisonAI (CVE‑2026‑39891).
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions in the input are executed rather than treated as literal text. This vulnerability is fixed in 4.5.115.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-04-08 | 2 | General1Patch1 |
| 2026-04-09 | 2 | Disclosure2 |

🔴 PraisonAI, Template Injection, #CVE-2026-39891 (High) https://dailycve.com/praisonai-template-injection-cve-2026-39891-high/
Post summary
The post announces a new high‑severity template injection vulnerability in PraisonAI (CVE‑2026‑39891).

[CVE-2026-39891: HIGH] Cyber security alert: Prior to version 4.5.115, PraisonAI had a vulnerability where user input could execute template expressions. Update to the latest version to stay protected.#cve,CVE-2026-39891,#cybersecurity https://cvefind.com/CVE-2026-39891
Post summary
PraisonAI’s CVE‑2026‑39891 allows template expression execution via user input; the text alerts users to deploy a patch by updating to version 4.5.115.

🚨*CVE* CVE-2026-39891 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content us… https://www.cve.org/CVERecord?id=CVE-2026-39891 ----- Traducción: CVE-2026-39891 Pra… http://infoflow.cloud`
Post summary
The post briefly references CVE-2026‑39891 in PraisonAI, noting a function that returns tools handling file content, but provides no exploit, patch, or active exploitation details.

CVE-2026-39891 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content us… https://www.cve.org/CVERecord?id=CVE-2026-39891
Post summary
CVE‑2026‑39891 affects PraisonAI’s create_agent_centric_tools() function, with the issue fixed in version 4.5.115; no PoC, exploit, or active exploitation reports are referenced.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | praison | praisonai | - | - | - |