CVE-2026-40288Patch(praison / praisonai)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch praison praisonai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. When praisonai workflow run <file.yaml> loads a YAML file with type: job, the JobWorkflowExecutor in job_workflow.py processes steps that support run: (shell commands via subprocess.run()), script: (inline Python via exec()), and python: (arbitrary Python script execution)—all without any validation, sandboxing, or user confirmation. The affected code paths include action_run() in workflow.py and _exec_shell(), _exec_inline_python(), and _exec_python_script() in job_workflow.py. An attacker who can supply or influence a workflow YAML file (particularly in CI pipelines, shared repositories, or multi-tenant deployment environments) can achieve full arbitrary command execution on the host system, compromising the machine and any accessible data or credentials. This issue has been fixed in versions 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai
  • praisonaiagents

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-14); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
praisonaipraisonaiagents

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-04-14: 4Mentions · 2026-04-15: 2Patch / Workaround · 2026-04-14: 2Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-15: 104-1404-15
Signal classification3 categories
Patch
350.0%
General
233.3%
Disclosure
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-144
Disclosure1General1Patch2
2026-04-152
General1Patch1
Full discourse6 posts
  • PulsePatch.io@pulsepatchio
    Patch

    `PraisonAI` is vulnerable to remote code execution (RCE) via `type: job` workflow YAML, CVE-2026-40288. Restrict workflow submission access. Monitor vendor for patches. #PraisonAI #RCE #Cybersecurity https://www.pulsepatch.io/posts/cve-2026-40288-praisonai-rce

    Post summary

    The post reports CVE‑2026‑40288 as an RCE vulnerability in PraisonAI’s job workflow YAML, recommends restricting workflow submission as a workaround, and advises monitoring for vendor patches.

    60050171
    14 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical vulnerabilities in #PraisonAI CVE-2026-40313, CVE-2026-40288, CVE-2026-40289. These vulnerabilities could enable system compromise, data exposure, or full takeover. Updates are available. #Patch #Patch #Patch

    Post summary

    The post highlights critical vulnerabilities in PraisonAI and informs readers that updates are available to mitigate the risks.

    00001190
    7.2K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-40288 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40288 #CVE-2026-40288 #CVE #Critical #CyberSecurity #InfoSec https://t.co/QkqCJKj86L

    Post summary

    The tweet announces the existence of CVE-2026-40288 with a high severity rating but offers no technical details, exploit information, or mitigation guidance.

    0000025
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40288 PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command… https://www.cve.org/CVERecord?id=CVE-2026-40288

    Post summary

    The post announces a new CVE affecting specific versions of PraisonAI, describing an arbitrary command execution flaw but providing no proof of exploitation, patch, or active attacks.

    0000049
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40288 Arbitrary Command and Code Execution in PraisonAI Below 4.5.139 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40288 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The CVE-2026-40288 vulnerability is described as allowing arbitrary command and code execution in PraisonAI versions below 4.5.139. No PoC, exploit, active exploitation, or patch information is provided.

    0000045
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-40288: CRITICAL] PraisonAI versions below 4.5.139 are vulnerable to arbitrary command execution through untrusted YAML files. Update to secure versions 4.5.139 to stay protected.#cve,CVE-2026-40288,#cybersecurity https://cvefind.com/CVE-2026-40288

    Post summary

    The text discloses CVE‑2026‑40288, describing arbitrary command execution through untrusted YAML files in PraisonAI versions prior to 4.5.139, and recommends updating to the patched 4.5.139 release.

    0000037
    620 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---
Apppraisonpraisonaiagents-python-

Explore more