Arbitrary Code Execution Vulnerability in PraisonAI by Mervin Praison
CVE-2026-41497
9.8CRITICAL
What is CVE-2026-41497?
PraisonAI, a multi-agent teams system, is vulnerable to arbitrary code execution due to insufficient validation in its MCP command handling mechanism. Versions before 4.6.9 allow potentially harmful executables and inline code execution flags to be processed without proper command allowlisting. This flaw can lead to unauthorized command execution in subprocesses, posing significant security risks. The vulnerability has been addressed in version 4.6.9, which implements necessary safeguards.
Affected Version(s)
PraisonAI < 4.6.9
