CVE-2026-57125

9.8

MervinPraison · PraisonAI

An unauthenticated remote code execution vulnerability in PraisonAI allows attackers to execute arbitrary operating system commands via the /api/v1/runs Jobs API.

Executive summary

A critical vulnerability in MervinPraison PraisonAI allows unauthenticated remote attackers to execute arbitrary system commands, posing a severe risk of full system compromise.

Vulnerability

This vulnerability involves missing authentication and incorrect authorization in the /api/v1/runs Jobs API, where an unauthenticated attacker can manipulate the agent_yaml configuration to bypass approval checks for critical tools. This allows the language model agent to execute arbitrary operating system commands without requiring any credentials or user interaction.

Business impact

The potential for unauthenticated remote code execution represents the highest level of security risk, as it allows attackers to gain full control over the host environment. Given the CVSS score of 9.8, this vulnerability could lead to total data exfiltration, unauthorized modification of sensitive internal resources, and complete service disruption. Organizations relying on PraisonAI for automated agent workflows must treat this as a high-priority remediation task to avoid potential system takeover.

Remediation

Immediate Action: Update the praisonai package to version 4.6.59 and the praisonaiagents package to version 1.6.59 immediately to apply the vendor-provided fixes.

Proactive Monitoring: Monitor server logs for unauthorized access attempts directed at the /api/v1/runs endpoint, particularly those originating from unknown or untrusted IP addresses.

Compensating Controls: Implement strict network-level access controls or a Web Application Firewall (WAF) to block external access to the API if an immediate update cannot be performed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability cannot be overstated given the lack of authentication required for successful exploitation. Security teams should prioritize the deployment of the patched versions across all instances of PraisonAI. Given the availability of proof-of-concept information, immediate action is required to close this critical security gap and prevent unauthorized remote code execution.

More MervinPraison CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources