Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-57125: PraisonAI allows unauthenticated remote code execution

CVE-2026-57125 · published 26 days ago
Summary

Versions of PraisonAI and PraisonAIAgents older than 4.6.59 and 1.6.59 let anyone send a specially crafted request to run arbitrary system commands. This can happen without a login or any user interaction, potentially compromising the server. Upgrade both components to the latest releases to close the issue.

What to do
  • Update mervin praison praisonaiagents to version 1.6.59.
  • Update mervin praison praisonai to version 4.6.59.
Affected software
Ecosystem VendorProductAffected versions
pip mervin praison praisonaiagents < 1.6.59
Fix: upgrade to 1.6.59
pip mervin praison praisonai <= 4.6.48
Fix: upgrade to 4.6.59
Original advisory text
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating-system commands without credentials or operator interaction. This vulnerability is fixed in praisonai 4.6.59 and praisonaiagents 1.6.59 as fixed versions.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.8 Critical
Type
CWE-306Missing Authentication for Critical Function
CWE-863Incorrect Authorization
Timeline
Published14 Sep 2026
Updated15 Sep 2026
First seen18 Jun 2026
Sources
Track software like this
Free during beta