CVE-2026-40088Disclosure(praison / praisonai)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch praison praisonai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls, allowing attackers to inject arbitrary shell commands through shell metacharacters. This vulnerability is fixed in 4.5.121.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 104-0904-1004-11
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure1General1Patch1
2026-04-101
Disclosure1
2026-04-111
Disclosure1
Full discourse5 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Multiple Critical vulnerabilities in #PraisonAI. e.g. CVE-2026-40088 and CVE-2026-40154 CVSS: 9.6. These vulnerabilities can lead to remote code execution #RCE in various different ways! More info: https://github.com/MervinPraison/PraisonAI/security #Patch #Patch #Patch

    Post summary

    The post alerts readers to two newly identified high‑severity CVEs (CVE‑2026‑40088, CVE‑2026‑40154) in PrinzAI that allow remote code execution, but it does not provide any proofs of exploitation or patch details.

    00002235
    7.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `PraisonAI` is affected by CVE-2026-40088, a critical OS Command Injection vulnerability. This flaw could enable arbitrary command execution. Monitor for security updates. #PraisonAI #OSCommandInjection #infosec https://www.pulsepatch.io/posts/cve-2026-40088-praisonai-os-command-injection

    Post summary

    The tweet announces that PraisonAI is affected by CVE-2026-40088, a critical OS command injection vulnerability enabling arbitrary command execution, and advises monitoring for updates, without providing PoC, exploit code, or patch details.

    0000050
    11 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-40088: CRITICAL] Critical cybersecurity update: PraisonAI fixed a vulnerability in version 4.5.121 that allowed attackers to inject shell commands via user-controlled input. Update now to stay secure.#cve,CVE-2026-40088,#cybersecurity https://cvefind.com/CVE-2026-40088

    Post summary

    The post announces that PraisonAI has released a patch for CVE‑2026‑40088, detailing a shell‑command injection flaw and urging users to update to mitigate the risk.

    0000033
    619 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40088 PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent wo… https://www.cve.org/CVERecord?id=CVE-2026-40088

    Post summary

    The message announces CVE‑2026‑40088 for PraisonAI, highlighting a command injection flaw in execute_command and workflow shell execution, but provides no PoC, exploit, or patch details.

    0000090
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40088: Impro... LLM-generated tool calls executing shell commands without sanitization = RCE paradise for prompt injection attacks. #CVE202640088 #RCE #AIHacking. https://zerodaysignal.com/vulnerability/CVE-2026-40088 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-40088 allows remote code execution via unsanitized LLM‑generated tool calls; no PoC, exploitation, or patch details are provided in the brief announcement.

    0000073
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more