PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions in the input are executed rather than treated as literal text. This vulnerability is fixed in 4.5.115.
References
| Link | Resource |
|---|---|
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg | Vendor Advisory Exploit |
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg | Vendor Advisory Exploit |
Configurations
History
22 Apr 2026, 16:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg - Vendor Advisory, Exploit | |
| CPE | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | |
| First Time |
Praison
Praison praisonai |
09 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hwg5-x759-7wjg - |
08 Apr 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-08 21:17
Updated : 2026-04-22 16:51
NVD link : CVE-2026-39891
Mitre link : CVE-2026-39891
CVE.ORG link : CVE-2026-39891
JSON object : View
Products Affected
praison
- praisonai
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
