---
id: CVE-2026-40287
aliases:
  - GHSA-g985-wjh9-qxxc
  - PYSEC-2026-2914
  - PYSEC-2026-2947
title: PraisonAI Vulnerable to RCE via Automatic tools.py Import
summary: PraisonAI Vulnerable to RCE via Automatic tools.py Import
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: praisonaiagents
product: praisonaiagents
ecosystem: pip
affected:
  - praisonaiagents < 1.5.140
  - praisonai < 4.5.139
patched:
  - praisonaiagents 1.5.140
  - praisonai 4.5.139
published: '2026-04-10'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-g985-wjh9-qxxc'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-g985-wjh9-qxxc
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40287'
  - url: 'https://github.com/MervinPraison/PraisonAI'
  - url: 'https://github.com/MervinPraison/PraisonAI/releases/tag/v4.5.139'
tags:
  - osv
  - pip
epss: 0.00231
epssPercentile: 0.12438
ingestedAt: '2026-07-13T18:57:58.205Z'
---

## Overview

PraisonAI automatically imports `./tools.py` from the current working directory when launching certain components. This includes call.py, tool_resolver.py, and CLI tool-loading paths.

A malicious tools.py placed in the process working directory is executed immediately, allowing arbitrary Python code execution in the host environment.

### Affected Code
- call.py → `import_tools_from_file()`
- tool_resolver.py → `_load_local_tools()`
- tools.py → local tool import flow
- 

### PoC
Create tools.py in the directory where PraisonAI is launched:

```python
# tools.py
import os
os.system("echo pwned > /tmp/pwned.txt")
```

Run any PraisonAI component that loads local tools, for example:

```bash
praisonai workflow run safe.yaml
```

### Reproduction Steps
1. Create a malicious tools.py in the current working directory.
2. Start PraisonAI or invoke a CLI command that loads local tools.
3. Verify that `/tmp/pwned.txt` or the malicious command output exists.

### Impact
An attacker who can place or influence tools.py in the working directory can execute arbitrary code in the PraisonAI process, compromising the host and any connected data.

**Reporter:** Lakshmikanthan K (letchupkt)

## Affected packages

- `praisonaiagents < 1.5.140`
- `praisonai < 4.5.139`

## Remediation

Upgrade to a patched release:

- `praisonaiagents 1.5.140`
- `praisonai 4.5.139`
