


Perceptive Security
SOC/SIEM Consultancy

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" …
Published:
5 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 23:03:13
Source:
nvd.nist.gov
Emerging Technologies, Supply Chain & Dependencies
CVE-2026-55522 affects PraisonAI, a multi-agent teams system, across versions 3.9.26–4.6.57 of praisonai and 0.12.12–1.6.57 of praisonaiagents. The vulnerability resides in the workflow 'include' feature, where Workflow._execute_include() loads and executes a recipe's tools.py using raw importlib calls without applying the required opt-in security gates or the centralized safe loader. This allows arbitrary module-level Python code to execute during include setup, before any workflow parsing or model invocation. The same vulnerable sink is also reachable via the praisonai.recipe.run() API. An attacker who can cause a victim process to include an attacker-controlled local recipe directory achieves arbitrary code execution as the PraisonAI process user. This bypasses previously applied hardening for the automatic tools.py RCE advisory family. The issue is fixed in praisonai 4.6.58 and praisonaiagents 1.6.58.
Technical details
Mitigation steps:
Affected products:
PraisonAI
praisonaiagents
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55522
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hxmv-c4g6-5fqc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
