Multi-Agent Teams System Vulnerability in PraisonAI
CVE-2026-57137

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-57137?

A vulnerability exists in the multi-agent teams system, PraisonAI, where the createAgentLoop() function allows executable tools to be passed to generateText() without proper approval from the onToolCall callback. As a result, unauthorized and potentially harmful operations can be executed even after the tool has been rejected. This flaw can lead to unintended side effects like executing rejected files, commands, APIs, or altering data. The issue has been remediated in version 1.7.2, ensuring that callbacks are respected to prevent adverse outcomes.

Affected Version(s)

PraisonAI >= 1.4.0, < 1.7.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.