PT-2026-31792 · Unknown · Praisonaiagents
Published
2026-04-09
·
Updated
2026-04-10
·
CVE-2026-40153
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PraisonAIAgents versions prior to 1.5.128
Description
PraisonAIAgents is a multi-agent teams system. The
execute command function in shell tools.py calls os.path.expandvars() on every command argument, allowing exfiltration of secrets stored in environment variables. The approval system displays unexpanded environment variable references to reviewers, creating a deceptive approval process where the displayed command differs from the executed command.Recommendations
Update to version 1.5.128 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonaiagents