LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40088

CVE-2026-40088 - Vulnerability Analysis

CriticalCVSS: 9.6

Last Updated: April 9, 2026

PraisonAI - Command Injection

Published: April 9, 2026Updated: April 9, 2026Remote Exploitable

Overview

PraisonAI < 4.5.121 contains a command injection caused by user-controlled input in execute_command function and workflow shell execution, letting attackers inject arbitrary shell commands, exploit requires crafted agent workflows or YAML definitions.

Severity & Score

Severity: Critical
CVSS Score: 9.6
EPSS Score: 5.2%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary shell commands, potentially leading to full system compromise.

Mitigation

Upgrade to version 4.5.121 or later.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 10, 2026

šŸ”“ CVE-2026-40088 - Critical (9.6) PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls, allowing attackers to in... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40088/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-40088
Severity
Critical
CVSS Score
9.6
Type
command_injection
Status
new
EPSS
5.2%
Social Posts
1

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Score

5.2%Probability of exploitation in the next 30 days