CVE-2026-44336Disclosure(praison / praisonai)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules.create, praisonai.rules.show, praisonai.rules.delete, and praisonai.workflow.show. Each accepts a path or filename string from MCP tools/call arguments and joins it onto ~/.praison/rules/ (or, for workflow.show, accepts an absolute path) with no containment check. The JSON-RPC dispatcher passes params["arguments"] blind to each handler via **kwargs without validating against the advertised input schema. By setting rule_name="../../<some-path>" an attacker walks out of the rules directory and writes any file the running user can write. Dropping a Python .pth file into the user site-packages directory escalates this primitive to arbitrary code execution in any subsequent Python process the user spawns — the next praisonai CLI invocation, an IDE script run, the user's python REPL, or any background Python service. This issue has been patched in version 4.6.34.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-22CWE-94CWE-829CWE-913

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 5 mentions (2026-05-14); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-05-08: 1Mentions · 2026-05-14: 5Mentions · 2026-06-16: 1Mentions · 2026-07-21: 1Technical Details · 2026-05-14: 4Technical Details · 2026-06-16: 105-0805-1406-1607-21
Signal classification2 categories
Disclosure
562.5%
General
337.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
General1
2026-05-145
Disclosure4General1
2026-06-161
Disclosure1
2026-07-211
General1
Full discourse8 posts
  • CVE@CVEnew
    General

    CVE-2026-47394 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description na… https://www.cve.org/CVERecord?id=CVE-2026-47394

    Post summary

    The notice mentions CVE-2026-47394 in the context of PraisonAI’s versioning and an incomplete fix for a related CVE, but offers no PoC, exploit details, patch information, or technical vulnerability specifics.

    00020871
    58.1K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-44336: critical severity (CVSS 9.6). Scope affected systems for a remote code execution issue. Scope it today so nobody has to explain it tomorrow.

    Post summary

    The text announces CVE-2026-44336 as a critical remote code execution vulnerability with CVSS 9.6, but provides no further detail on exploitation, patches, or proof of concept.

    1000048
    337 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-44336 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical advisory for CVE‑2026‑44336, listing its CVSS score of 9.6 and associated severity information.

    1000039
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-44336 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE-2026-44336 with a critical CVSS score of 9.6, indicating severe confidentiality, integrity, and availability impact, but provides no further details on exploitation or mitigation.

    1000027
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-44336 (CVSS 9.6) — praison praisonai. CVE: CVE-2026-44336 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The message announces CVE‑2026‑44336, a critical vulnerability with detailed CVSS metrics, but does not mention a PoC, exploit code, active exploitation, patch, or false positive claim.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-44336 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory PraisonAI is a multi-agent teams system.

    Post summary

    CVE-2026-44336 is a newly disclosed critical vulnerability with a CVSS score of 9.6, but no PoC, exploit, or patch information is provided.

    1000032
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-44336-praison-praisonai #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet shares a link to a research page on CVE‑2026‑44336 without providing additional context or specific details.

    0000016
    210 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44336 PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling t… https://www.cve.org/CVERecord?id=CVE-2026-44336

    Post summary

    The passage notes a file‑handling issue in PraisonAI's MCP server before version 4.6.34 and links to the CVE record, but provides no information on exploits, patches, or detailed technical aspects.

    00000123
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more