PT-2026-31792 · Unknown · Praisonaiagents

Published

2026-04-09

·

Updated

2026-04-10

·

CVE-2026-40153

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PraisonAIAgents versions prior to 1.5.128
Description PraisonAIAgents is a multi-agent teams system. The execute command function in shell tools.py calls os.path.expandvars() on every command argument, allowing exfiltration of secrets stored in environment variables. The approval system displays unexpanded environment variable references to reviewers, creating a deceptive approval process where the displayed command differs from the executed command.
Recommendations Update to version 1.5.128 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-40153
GHSA-V8G7-9Q6V-P3X8

Affected Products

Praisonaiagents