Executive brief
PraisonAI is a framework used to build and manage teams of AI agents. A security flaw in how the system loads custom tools allows an attacker to execute malicious code on the host server. This can occur if the system is configured to load a malicious configuration file or if an attacker can influence the tool paths used by the agents, potentially leading to a full system takeover or data theft.
Technical details
A code injection vulnerability exists in `praisonai/agents_generator.py` within the `load_tools_from_module` and `load_tools_from_module_class` functions. These functions utilize `spec.loader.exec_module` to load Python modules from paths specified in YAML configuration files (e.g., `agents.yaml`). Unlike other parts of the application patched in previous security updates, these specific call sites lacked validation, signature checking, or the `PRAISONAI_ALLOW_LOCAL_TOOLS` environment variable gate. An attacker can exploit this by supplying a malicious `module_path` via a shared configuration directory, a remote recipe (e.g., via GitHub), or through prompt injection that influences agent orchestration. Successful exploitation results in arbitrary Python code execution during the tool registry construction phase.
Affected products
- MervinPraison PraisonAI < 4.6.40
Timeline
- 2026-05-19: patched: Fix included in version 4.6.40 via commit ef79b7a
- 2026-07-21: advisory: GHSA-78r8-wwqv-r299 published