Junglewise Threat Intelligence

CVE-2026-40111: MervinPraison PraisonAIAgents OS command injection in Memory Hooks Executor

CVE-2026-40111 · Severity: critical · CVSS 4 · Published 2026-04-10

Technologies: praisonaiagents (PyPI), MervinPraison PraisonAI Agents. Vendors: PyPI, MervinPraison.

Executive brief

PraisonAIAgents is a framework for building and managing AI agents. A vulnerability in its memory hooks component allows an attacker to execute arbitrary system commands on the host machine. This can occur if an attacker can modify a configuration file or influence agent prompts, potentially leading to full system takeover, data theft, or persistent backdoors in automated environments.

Technical details

The vulnerability exists in `src/praisonai-agents/praisonaiagents/memory/hooks.py` where user-controlled command strings from `hooks.json` are passed directly to `subprocess.run()` with `shell=True`. The application lacks any sanitization or validation (such as `shlex.quote()` or allowlisting) for these commands. Attackers can exploit this via two surfaces: directly through hook event configurations or indirectly via prompt injection if an agent has file-write access to the workspace, allowing it to overwrite `.praisonai/hooks.json`. This enables arbitrary command execution with the privileges of the agent process and allows for persistent backdoors that trigger during standard lifecycle events like `BEFORE_TOOL` or `AFTER_TOOL`. A fix is available in version 1.5.128.

Affected products

  • MervinPraison praisonaiagents <= 1.5.126

Timeline

  • 2026-04-09: disclosed
  • 2026-04-10: advisory: GHSA-v7px-3835-7gjx published
  • 2026-04-10: patched: Fixed in version 1.5.128

References

Related threats