CVE-2026-44334General(praison / praisonai)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch praison praisonai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_TOOLS=true in two files (tool_resolver.py, api/call.py). A third import sink in praisonai/templates/tool_override.py was missed and remains unguarded. It is reached by the recipe runner on every recipe execution and is remotely triggerable through POST /v1/recipes/run with a recipe value pointing at any local absolute path or any GitHub repo (because SecurityConfig.allow_any_github defaults to True). The attacker drops a tools.py next to TEMPLATE.yaml; the server exec_module()s it. No auth required by default, no environment opt-in required. This issue has been patched in version 4.6.32.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-07); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-05-09: 2Mentions · 2026-06-07: 3Mentions · 2026-07-21: 1Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-06-07: 3Technical Details · 2026-06-07: 205-0906-0707-21
Signal classification2 categories
General
350.0%
Patch
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-092
General1Patch1
2026-06-073
General1Patch2
2026-07-211
General1
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Patch

    The Patch That Missed: CVE-2026-44334 Breaks PraisonAI Again—Unauthenticated RCE in AI Agent Framework. Timeline: April 14, 2026: CVE-2026-40287 disclosed—PraisonAI's http://tools.py auto-import vulnerability allowed RCE April 2026: PraisonAI v4.5.139 released a patch adding…

    Post summary

    The snippet highlights a recently disclosed CVE that caused unauthenticated RCE in PraisonAI and notes that a patch was released, though the fix omitted the issue.

    1000025
    253 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    The original CVE-2026-40287 fix added environment variable checks to: praisonai/toolresolver.py (line 77) praisonai/api/call.py (line 80) The Patch That Missed: CVE-2026-44334 Breaks PraisonAI Again—Unauthenticated RCE in AI Agent Framework

    Post summary

    An earlier patch for CVE‑2026‑40287 added environment variable checks, yet a new CVE‑2026‑44334 introduces an unauthenticated RCE in PraisonAI’s AI Agent Framework, highlighting a missed vulnerability.

    1000026
    253 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-47398 PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS en… https://www.cve.org/CVERecord?id=CVE-2026-47398

    Post summary

    The text references CVE-2026-47398 but provides no PoC, exploit details, patch information, technical specifics, or evidence of active exploitation.

    000001.1K
    57.8K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-05-07-praisonai-cve-2026-44334-incomplete-patch-bypass #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    Only a URL and a brief description are given, indicating a research post about CVE‑2026‑44334 with an incomplete patch bypass, but no actionable details or evidence of exploitation.

    0000022
    253 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-44334 PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated http://tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_T… https://www.cve.org/CVERecord?id=CVE-2026-44334 ----- Traducción: CVE… http://infoflow.cloud`

    Post summary

    The post is a brief mention of CVE-2026-44334 with a link to its CVE record but offers no PoC, exploit, patch information, or detailed technical context.

    0000016
    76 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-44334 PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated http://tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_T… https://www.cve.org/CVERecord?id=CVE-2026-44334

    Post summary

    The text references CVE‑2026‑44334 and notes a fix for CVE‑2026‑40287 involving gating auto‑import, but it provides no PoC, exploit, or evidence of active exploitation.

    00000164
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more