TopVuln

High-risk vulnerability digests

CVE-2026-40288

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-04-14 04:17:12
EPSS
0.1% probability · 26.2th percentile — 2026-05-12
Affected versions
PraisonAI < 4.5.139, praisonaiagents < 1.5.140
Summary
PraisonAI, a widely used multi-agent AI system, is vulnerable to arbitrary command and code execution through unvalidated YAML workflow files. The workflow engine executes shell commands and Python code from loaded YAML files without any sandboxing, validation, or user confirmation. An attacker able to supply a malicious YAML file can achieve full code execution on the host system.
Remediation
Upgrade PraisonAI to version 4.5.139 or later, and praisonaiagents to version 1.5.140 or later immediately. Avoid loading YAML workflow files from untrusted or shared sources before upgrading. Audit existing workflows for malicious content to rule out prior compromise.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.