CVE-2026-40288
PraisonAI has critical RCE via `type: job` workflow YAML
Summary
Remediation
Upgrade to the fixed version using your package manager.
pip install "praisonai>=4.5.139"
pip install "praisonaiagents>=1.5.140"
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (2)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| praisonai | pypi | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+691 more) | 4.5.139 |
| praisonaiagents | pypi | 0.0.1, 0.0.10, 0.0.100, 0.0.101 (+515 more) | 1.5.140 |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Frequently Asked Questions
- What is CVE-2026-40288?
- PraisonAI has critical RCE via `type: job` workflow YAML This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
- How do I check if my project is affected by CVE-2026-40288?
- CVE-2026-40288 affects praisonai and praisonaiagents. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-40288 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation is straightforward and causes maximum impact. Patch immediately.
Also Known As
Related CVEs
- CVE-2026-40289CRITICAL
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
- CVE-2026-34953CRITICAL
PraisonAI Has Authentication Bypass via OAuthManager.validate_token()
- CVE-2026-40157CRITICAL
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
- CVE-2026-57125CRITICAL
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
- CVE-2026-47392CRITICAL
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
- CVE-2026-34938CRITICAL
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
- CVE-2026-47393CRITICAL
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
- CVE-2026-40289CRITICAL
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies