Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57125: PraisonAI allows unauthenticated remote code execution
CVE-2026-57125 · published 26 days ago
Summary
Versions of PraisonAI and PraisonAIAgents older than 4.6.59 and 1.6.59 let anyone send a specially crafted request to run arbitrary system commands. This can happen without a login or any user interaction, potentially compromising the server. Upgrade both components to the latest releases to close the issue.
What to do
- Update mervin praison praisonaiagents to version 1.6.59.
- Update mervin praison praisonai to version 4.6.59.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | mervin praison | praisonaiagents |
< 1.6.59 Fix: upgrade to 1.6.59
|
| pip | mervin praison | praisonai |
<= 4.6.48 Fix: upgrade to 4.6.59
|
Original advisory text
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating-system commands without credentials or operator interaction. This vulnerability is fixed in praisonai 4.6.59 and praisonaiagents 1.6.59 as fixed versions.
References
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4869-x4pr-q2... Vendor Advisory
- https://github.com/advisories/GHSA-4869-x4pr-q22x
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57125... Vendor Advisory
- https://github.com/MervinPraison/PraisonAI/commit/2adfe7e8323f6deec66925cf15a885... Patch
- https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.59 URL
- https://nvd.nist.gov/vuln/detail/CVE-2026-57125 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Type
CWE-306Missing Authentication for Critical Function
CWE-863Incorrect Authorization
Timeline
Published14 Sep 2026
Updated15 Sep 2026
First seen18 Jun 2026
Track software like this
Free during beta