Shell Command Injection Vulnerability in PraisonAI by MervinPraison
CVE-2026-40088
9.7CRITICAL
What is CVE-2026-40088?
The PraisonAI platform, designed for multi-agent teams, contains a vulnerability that allows for shell command injection through the execute_command function. This vulnerability stems from the handling of user-controlled input within agent workflows, YAML definitions, and LLM-generated tool calls. Attackers can exploit this flaw to inject arbitrary shell commands by utilizing shell metacharacters, potentially compromising system integrity. The issue has been addressed and resolved in version 4.5.121.
Affected Version(s)
PraisonAI < 4.5.121
