CVE-2026-39891

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions in the input are executed rather than treated as literal text. This vulnerability is fixed in 4.5.115.
Configurations

Configuration 1 (hide)

cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*

History

22 Apr 2026, 16:51

Type Values Removed Values Added
References () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg - () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg - Vendor Advisory, Exploit
CPE cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*
First Time Praison
Praison praisonai

09 Apr 2026, 14:16

Type Values Removed Values Added
References () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg - () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg -

08 Apr 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 21:17

Updated : 2026-04-22 16:51


NVD link : CVE-2026-39891

Mitre link : CVE-2026-39891

CVE.ORG link : CVE-2026-39891


JSON object : View

Products Affected

praison

  • praisonai
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')