CVE-2026-40287Patch(praison / praisonai)

LOWCVSS 8.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch praison praisonai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py (_load_local_tools()), and CLI tool-loading paths blindly import ./tools.py at startup without any validation, sandboxing, or user confirmation. An attacker who can place a malicious tools.py in the directory where PraisonAI is launched (such as through a shared project, cloned repository, or writable workspace) achieves immediate arbitrary Python code execution in the host environment. This compromises the full PraisonAI process, the host system, and any connected data or credentials. This issue has been fixed in version 4.5.139.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-426

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai
  • praisonaiagents

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-06-07)
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
praisonaipraisonaiagents

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-05-07: 1Mentions · 2026-05-09: 2Mentions · 2026-06-07: 3Patch / Workaround · 2026-05-09: 2Patch / Workaround · 2026-06-07: 3Technical Details · 2026-04-14: 2Technical Details · 2026-05-07: 1Technical Details · 2026-06-07: 304-1404-1505-0705-0906-07
Signal classification3 categories
Patch
555.6%
Disclosure
333.3%
General
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure2
2026-04-151
General1
2026-05-071
Disclosure1
2026-05-092
Patch2
2026-06-073
Patch3
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    Patch

    The Patch That Missed: CVE-2026-44334 Breaks PraisonAI Again—Unauthenticated RCE in AI Agent Framework. Timeline: April 14, 2026: CVE-2026-40287 disclosed—PraisonAI's http://tools.py auto-import vulnerability allowed RCE April 2026: PraisonAI v4.5.139 released a patch adding…

    Post summary

    CVE‑2026-44334 is an unauthenticated RCE affecting PraisonAI’s AI Agent Framework; a patch was released (v4.5.139), but no PoC, exploit code, or active exploitation evidence is provided.

    1000025
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The original CVE-2026-40287 fix added environment variable checks to: praisonai/toolresolver.py (line 77) praisonai/api/call.py (line 80) The Patch That Missed: CVE-2026-44334 Breaks PraisonAI Again—Unauthenticated RCE in AI Agent Framework

    Post summary

    The text outlines a patch that added environment variable checks for CVE-2026-40287, while noting that a separate CVE-2026-44334 still allows unauthenticated RCE in PraisonAI, indicating a missed patch issue.

    1000026
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Timeline: April 14, 2026: CVE-2026-40287 disclosed—PraisonAI's http://tools.py auto-import vulnerability allowed RCE April 2026: PraisonAI v4.5.139 released a patch adding environment variable gating (PRAISONAIALLOWLOCALTOOLS=true) to two code paths May 5-6, 2026: Security…

    Post summary

    The text announces CVE‑2026‑40287 as an RCE vulnerability, reports a patch with an environment variable workaround, and provides technical details about the issue.

    1000016
    253 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-44334 PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated http://tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_T… https://www.cve.org/CVERecord?id=CVE-2026-44334 ----- Traducción: CVE… http://infoflow.cloud`

    Post summary

    The post mentions CVE-2026-44334 and cites a fix for CVE-2026-40287, but offers no PoC, exploit code, or detailed vulnerability information.

    0000016
    76 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-44334 PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated http://tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_T… https://www.cve.org/CVERecord?id=CVE-2026-44334

    Post summary

    The post indicates that a fix for CVE-2026-40287 is gated behind an environment variable in PraisonAI, but it offers no PoC, active exploitation, or detailed vulnerability data.

    00000164
    57.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PraisonAI, Remote Code Execution (RCE), #CVE-2026-40287 (Critical) https://dailycve.com/praisonai-remote-code-execution-rce-cve-2026-40287-critical/

    Post summary

    The post announces a critical Remote Code Execution vulnerability (CVE‑2026‑40287) in PraisonAI and directs readers to a DailyCVE link for additional information.

    0000038
    196 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-40287 📊 Severity: 8.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40287 #CVE-2026-40287 #CVE #High #CyberSecurity #InfoSec https://t.co/Dx6Jm7zi7u

    Post summary

    The tweet simply announces the existence of CVE-2026-40287 with severity information, providing no details on PoC, exploit, patch, or active usage.

    0000032
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40287 PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a http://tools.py fil… https://www.cve.org/CVERecord?id=CVE-2026-40287

    Post summary

    The post discloses that PraisonAI versions 4.5.138 and below are susceptible to arbitrary code execution via an unsanitized http://tools.py import, describing a new CVE.

    0000050
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40287 Arbitrary Code Execution in PraisonAI Versions 4.5.138 and Below via Unsanitized http://tools.py Import https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40287

    Post summary

    The post announces a new CVE‑2026‑40287 vulnerability that allows arbitrary code execution in PraisonAI versions 4.5.138 and below, caused by an unsanitized import of http://tools.py, with a link to a Vulmon page for further details.

    0000044
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---
Apppraisonpraisonaiagents-python-

Explore more