External risk intelligence

PraisonAI Agents Remote Command Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-57125

The vulnerability affects an API endpoint (/api/v1/runs) within a multi-agent systems framework. Such APIs are commonly deployed as web services or backend endpoints intended for remote or programmatic access, making them likely to be reachable in network-exposed configurations.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the PraisonAI multi-agent system that could allow unauthenticated attackers to execute arbitrary operating-system commands remotely. This issue arises from the way job requests are handled, potentially enabling malicious actors to bypass approval checks and command execution safeguards. The main concern at this time is confirming if PraisonAI is in use and if it is exposed to external access.

  • Attackers can run any command remotely.
  • It affects AI systems that automate tasks.
  • Confirm usage and external exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the system's API. This request would leverage a flaw in how job approvals are handled, allowing the attacker to bypass necessary checks and trick a language model agent into executing arbitrary commands on the underlying operating system. This attack requires no prior authentication or special privileges, and can be initiated remotely.

  • Unauthenticated network access required.
  • Approving YAML for command execution.
  • Remote command execution risk.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary operating-system commands on the system. This is possible when the system is running unsupported versions and an attacker crafts a malicious request to the /api/v1/runs Jobs API.

  • System commands could be executed.
  • Unauthenticated API calls can trigger command execution.
  • Unauthorized system control may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in PraisonAI allows unauthenticated remote command execution. System owners and platform teams should prioritize identifying all instances of the affected technology, assessing their network exposure and business criticality, and confirming ownership for remediation. The immediate first step is to locate and inventory all PraisonAI deployments to understand the scope of the risk.

  • Identify PraisonAI deployments and their owners.
  • Verify network reachability and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI?

PraisonAI is a framework designed for building and managing multi-agent systems. It allows users to orchestrate teams of AI agents that automate tasks by interacting with language models. These agents can be configured to perform various operations, including executing system-level commands, making it a powerful tool for workflow automation.

What does CWE-306 and CWE-863 mean for CVE-2026-57125?

These codes identify a missing authentication step (CWE-306) and incorrect authorization (CWE-863). In the context of this CVE, it means the API fails to verify who is sending a request and does not properly check if they have permission to approve actions. This allows an unauthorized person to bypass security controls that would normally prevent an agent from running dangerous commands.

How is this vulnerability triggered?

An attacker triggers this by sending a specially crafted request to the /api/v1/runs endpoint without needing any credentials. The request includes malicious YAML data that falsely signals to the system that a command has already been approved. Simply interacting with the API is not inherently malicious; the bug requires the specific inclusion of this manipulated approval data to bypass the security logic.

Is my PraisonAI deployment at risk?

According to Halo Surface Signal, this vulnerability is considered likely to be reachable if your instance is network-exposed. Because the affected API endpoint is designed for programmatic or remote communication, any instance accessible over the internet or a wide internal network is at higher risk. You should prioritize instances that are not restricted to private, local-only access.

What should I do to secure my system?

The most effective first step is to identify and inventory all instances of PraisonAI running in your environment to understand your exposure. Once located, verify the version you are using. To resolve the security gap, you must update your installation to version 4.6.59 or later, as this update introduces the necessary checks to prevent unauthorized command execution.

References