CVE-2026-39891

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions in the input are executed rather than treated as literal text. This vulnerability is fixed in 4.5.115.
Configurations

Configuration 1 (hide)

cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-08 21:17

Updated : 2026-07-24 21:10


NVD link : CVE-2026-39891

Mitre link : CVE-2026-39891

CVE.ORG link : CVE-2026-39891


JSON object : View

Products Affected

praison

  • praisonai
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')