CVE-2026-57125Critical· 9.8▾ AbyssalPoC availablePraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
Last analysed / modified upstream
0.4%
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating-system commands without credentials or operator interaction. This vulnerability is fixed in praisonai 4.6.59 and praisonaiagents 1.6.59 as fixed versions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonai < 4.6.59praisonaiagents < 1.6.59Patched in:
praisonai 4.6.59praisonaiagents 1.6.59Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57112High· 8.3PraisonAI is a multi-agent teams system
CVE-2026-57124Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57119High· 7.5PraisonAI is a multi-agent teams system
CVE-2026-56839High· 7.3PraisonAI is a multi-agent teams system
CVE-2026-57122High· 8.6PraisonAI is a multi-agent teams system
CVE-2026-57123Critical· 9.8PraisonAI is a multi-agent teams system