criticalOther UnknownPublish anonymously
PraisonAI Quadruple CVE Disclosure
by Publish anonymously · 2 days agoviews 0en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
Four critical/high vulnerabilities in PraisonAI multi-agent framework: CVE-2026-39888 (CVSS 9.9) sandbox escape via exception frame traversal; CVE-2026-39890 (CVSS 9.8) RCE via YAML deserialization with `!!js/function` tags; CVE-2026-39891 (CVSS 8.8) template injection in agent tool definitions; CVE-2026-39889 (CVSS 7.5) unauthenticated SSE event stream exposes all agent activity. Fixed in 4.5.115.