Junglewise Threat Intelligence

CVE-2026-47398: MervinPraison PraisonAI code injection in agents_generator.py

CVE-2026-47398 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: praisonai (PyPI). Vendors: MervinPraison, PyPI.

Executive brief

PraisonAI is a framework used to build and manage teams of AI agents. A security flaw in how the system loads custom tools allows an attacker to execute malicious code on the host server. This can occur if the system is configured to load a malicious configuration file or if an attacker can influence the tool paths used by the agents, potentially leading to a full system takeover or data theft.

Technical details

A code injection vulnerability exists in `praisonai/agents_generator.py` within the `load_tools_from_module` and `load_tools_from_module_class` functions. These functions utilize `spec.loader.exec_module` to load Python modules from paths specified in YAML configuration files (e.g., `agents.yaml`). Unlike other parts of the application patched in previous security updates, these specific call sites lacked validation, signature checking, or the `PRAISONAI_ALLOW_LOCAL_TOOLS` environment variable gate. An attacker can exploit this by supplying a malicious `module_path` via a shared configuration directory, a remote recipe (e.g., via GitHub), or through prompt injection that influences agent orchestration. Successful exploitation results in arbitrary Python code execution during the tool registry construction phase.

Affected products

  • MervinPraison PraisonAI < 4.6.40

Timeline

  • 2026-05-19: patched: Fix included in version 4.6.40 via commit ef79b7a
  • 2026-07-21: advisory: GHSA-78r8-wwqv-r299 published

References

Related threats