Executive brief
PraisonAI, a system for managing multi-agent AI teams, contained a critical security flaw in its official server examples. An attacker could remotely execute their own code on the server without needing a password by sending a specially crafted message that triggers an unsafe calculation tool. This could allow an unauthorized user to take full control of the server, access sensitive data, or disrupt AI operations.
Technical details
The vulnerability arises from a combination of missing authentication in the Agent-to-Agent (A2A) JSON-RPC endpoint and the use of Python's `eval()` function in a registered `calculate(expression)` tool. In the official A2A server example, the server binds to `0.0.0.0` without an `auth_token`. A remote, unauthenticated attacker can send a `message/send` request to the `/a2a` endpoint; the system passes this input to `agent.chat()`, where a Large Language Model (LLM) may invoke the `calculate` tool using attacker-supplied strings. This results in arbitrary Python execution within the server process. The issue was addressed in version 4.6.40 by replacing `eval()` with an AST-based safe evaluator and hardening default authentication settings.
Affected products
- MervinPraison PraisonAI < 4.6.40
Timeline
- 2026-05-19: advisory: Initial GitHub security advisory published
- 2026-06-02: patched: Fix merged into main branch via PR #1793
- 2026-07-21: disclosed: CVE-2026-47391 published to NVD