External risk intelligence

PraisonAI Code Mode Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-57141

PraisonAI is a multi-agent framework. While such tools can be integrated into internet-facing applications or API services, they are also frequently used in internal development environments, local research projects, or private automation workflows. Exposure depends entirely on how the library is deployed and whether the tool interface is exposed to external users.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the PraisonAI multi-agent teams system that could allow unauthorized access to host process capabilities, including file system access, credential retrieval, and command execution. This issue arises from improper handling of model-generated JavaScript, potentially exposing sensitive operations if an attacker can influence the code input. The main concern is confirming relevance and exposure within your specific deployment.

  • System can be commanded by attackers.
  • It affects core system functions and data.
  • Assess if this system is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by influencing the `code` argument passed to the `codeMode` tool within PraisonAI. This allows them to bypass security measures and execute arbitrary JavaScript, gaining access to the host's process capabilities, including reading or writing files, accessing credentials, and running commands.

  • No privileges or user interaction needed.
  • Influencing the `code` argument.
  • Full host system compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker could exploit this vulnerability to access host process capabilities, potentially reading or writing files, obtaining environment credentials, or executing operating-system commands with the PraisonAI process privileges.

  • Host process capabilities at risk.
  • By influencing code execution.
  • Unauthorized file and command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability in the PraisonAI system. The first practical step is to identify all instances of PraisonAI, determine their exposure and criticality, and then locate the accountable owner to plan remediation.

  • Identify PraisonAI instances and owners.
  • Verify external reachability and criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI?

PraisonAI is a framework designed to manage and orchestrate teams of AI agents. Developers use it to automate complex tasks by coordinating multiple AI models to work together. Because it handles AI-generated logic and interacts with system tools, it is often found in research environments, custom automation workflows, or integrated into larger software platforms.

How does CVE-2026-57141 impact software security?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). It occurs because the software insecurely handles model-generated JavaScript. When the application executes this code, it does not properly sandbox the logic. Consequently, an attacker can bypass built-in restrictions to run arbitrary commands, access files, or steal credentials directly from the host system where PraisonAI is running.

When does this vulnerability trigger?

The issue triggers when an attacker successfully influences the code argument passed to the codeMode tool. If the input is not strictly controlled or sanitized, the underlying system executes the malicious payload. Simply running PraisonAI without exposing the codeMode tool to untrusted input or external data sources does not necessarily trigger this specific execution path.

Is my PraisonAI instance at risk?

According to Halo Surface Signal, risk depends on your specific deployment architecture. If your PraisonAI instance is part of an internet-facing application or API service, it faces a higher likelihood of external interaction. If it is restricted to internal research or private automation, the potential for unauthorized external access is reduced, though local security practices still apply.

How should I respond to this threat?

Start by identifying all instances of PraisonAI deployed within your environment. Once you have an inventory, confirm which versions are in use and determine if they are exposed to untrusted inputs. If you are running a version prior to 1.7.2, prioritize updating to the latest secure version to remediate the code execution risk, and work with your system owners to verify the fix.

References