Multi-Agent Teams System Vulnerability in PraisonAI
CVE-2026-57137
8.8HIGH
What is CVE-2026-57137?
A vulnerability exists in the multi-agent teams system, PraisonAI, where the createAgentLoop() function allows executable tools to be passed to generateText() without proper approval from the onToolCall callback. As a result, unauthorized and potentially harmful operations can be executed even after the tool has been rejected. This flaw can lead to unintended side effects like executing rejected files, commands, APIs, or altering data. The issue has been remediated in version 1.7.2, ensuring that callbacks are respected to prevent adverse outcomes.
Affected Version(s)
PraisonAI >= 1.4.0, < 1.7.2
