Junglewise Threat Intelligence

CVE-2026-57125: PraisonAI unauthenticated remote code execution via /api/v1/runs

CVE-2026-57125 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Technologies: praisonaiagents (PyPI), praisonai (PyPI). Vendors: PyPI, PraisonAI.

Executive brief

PraisonAI is a multi-agent system that orchestrates AI workflows using language models and tools. An unauthenticated attacker can send a malicious POST request to the /api/v1/runs API endpoint to inject arbitrary operating system commands, bypassing safety checks and causing the configured AI agent to execute those commands with the application's privileges. This results in complete system compromise with no authentication or user interaction required.

Technical details

The vulnerability is an authentication bypass and arbitrary command execution chain in the /api/v1/runs POST endpoint. An unauthenticated attacker can submit a crafted request containing a malicious agent_yaml payload with an approve field that pre-marks execute_command tools as "YAML-approved" before the @require_approval decorator performs critical tool safety checks. The vulnerable code logic allows the approval status to be set via attacker-controlled input, bypassing intended access control mechanisms. This enables remote code execution as the application user without credentials or operator consent. The fix (praisonai 4.6.59 and praisonaiagents 1.6.59) hardens input validation and access controls, properly enforcing approval requirements for critical tools.

Affected products

  • PraisonAI PraisonAI prior to 4.6.59
  • PraisonAI PraisonAI Agents prior to 1.6.59

Timeline

  • 2026-09-14: disclosed: CVE-2026-57125 published
  • 2026-06-13: patched: Fix committed to repository
  • 2026-06-17: other: v4.6.59 released with security patch

References

Related threats