Loading...
Skip to main content

CVE-2026-40288

CRITICAL

PraisonAI has critical RCE via `type: job` workflow YAML

Published April 10, 2026Updated June 29, 2026Source: osv

Summary

`praisonai workflow run <file.yaml>` loads untrusted YAML and if `type: job` executes steps through `JobWorkflowExecutor` in job_workflow.py. This supports: - `run:` → shell command execution via `subprocess.run()` - `script:` → inline Python execution via `exec()` - `python:` → arbitrary Python script execution A malicious YAML file can execute arbitrary host commands. ### Affected Code - workflow.py → `action_run()` - job_workflow.py → `_exec_shell()`, `_exec_inline_python()`, `_exec_python_script()` ### PoC Create `exploit.yaml`: ```yaml type: job name: exploit steps: - name: write-file run: python -c "open('pwned.txt','w').write('owned')" ``` Run: ```bash praisonai workflow run exploit.yaml ``` ### Reproduction Steps 1. Save the YAML above as `exploit.yaml`. 2. Execute `praisonai workflow run exploit.yaml`. 3. Confirm `pwned.txt` appears in the working directory. ### Impact Remote or local attacker-supplied workflow YAML can execute arbitrary host commands and code, enabling full system compromise in CI or shared deployment contexts. **Reporter:** Lakshmikanthan K (letchupkt)

Remediation

Upgrade to the fixed version using your package manager.

pip
Update praisonai to 4.5.139 or later
pip install "praisonai>=4.5.139"
pip
Update praisonaiagents to 1.5.140 or later
pip install "praisonaiagents>=1.5.140"

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (2)

PackageEcosystemAffectedFixed In
praisonai
pypi
0.0.1, 0.0.10, 0.0.11, 0.0.12 (+691 more)4.5.139
praisonaiagents
pypi
0.0.1, 0.0.10, 0.0.100, 0.0.101 (+515 more)1.5.140

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2026-40288?
PraisonAI has critical RCE via `type: job` workflow YAML This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
How do I check if my project is affected by CVE-2026-40288?
CVE-2026-40288 affects praisonai and praisonaiagents. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-40288 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.8

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-vc46-vw85-3wvm
PYSEC-2026-477
PYSEC-2026-488

Related CVEs

  • CVE-2026-40289
    CRITICAL

    PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

  • CVE-2026-34953
    CRITICAL

    PraisonAI Has Authentication Bypass via OAuthManager.validate_token()

  • CVE-2026-40157
    CRITICAL

    PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`

  • CVE-2026-57125
    CRITICAL

    PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass

  • CVE-2026-47392
    CRITICAL

    PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)

  • CVE-2026-34938
    CRITICAL

    PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code

  • CVE-2026-47393
    CRITICAL

    PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default

  • CVE-2026-40289
    CRITICAL

    PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies