CVE
CVE-2026-57125
0field notes · 1digest CVSS 9.8
The verdict
An attacker can hit the PraisonAI Jobs API without any authentication and submit crafted YAML that pre-approves dangerous tools like execute_command. The result: the AI agent will run whatever OS commands the attacker wants, no credentials or user interaction needed. CVSS 9.8, and the attack surface is a wide-open API endpoint, so treat this as a hair-on-fire issue if you expose PraisonAI to any network.
Patch urgency · Patch immediately
Daily digests