← Back to the live CVE advisory feed

CVE-2026-57138: PraisonAI

Severity
9.9 (CRITICAL)
Vendor
MERVINPRAISON
Affected versions
PraisonAI versions >= 1.4.0 and < 1.7.2
Fixed version
1.7.2
Patch status
Patched
Published
2026-09-15T11:17:11.180
Modified
2026-09-15T14:45:28.563

Why it matters

This vulnerability allows unauthenticated attackers to escape the sandbox in PraisonAI's codeMode, leading to arbitrary code execution on the host system. This can result in data theft, system compromise, or service disruption. Immediate patching is crucial to prevent severe impact.

Recommended admin actions

  • Upgrade PraisonAI to version 1.7.2 or later immediately.
  • Review access controls and network segmentation for PraisonAI deployments.
  • Monitor PraisonAI logs for any suspicious activity indicative of sandbox escape or unauthorized command execution.
  • Implement least privilege principles for the PraisonAI application's execution environment.

Technical summary

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use ({}).constructor.constructor to recover the real Function constructor, obtain process and process.mainModule.require, and reach host filesystem and subprocess APIs despite the advertised sandbox. Attackers who control codeMode input can read secrets, modify files, execute commands, or exhaust the host process. This issue is fixed in version 1.7.2.

AI-enriched (HIGH confidence). Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 15, 2026 08:00 PM UTC
991 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-59971
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-53710
mcp-context-forge PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-16338
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-57138
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-45579
DIRAC PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-61667
DIRAC PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-54333
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-54334
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-55209
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-65414
Product identification pending PATCH
Reporter: PRODUCT-SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-62379
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-57139
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-57141
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-57147
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-57148
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-63695
Product identification pending PATCH
Reporter: SECURITY_ALERT
9.8
CRITICAL
VIEW RECORD
CVE-2026-55211
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-12351
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-19773
libwebsockets
Reporter: ZDI-DISCLOSURES
9.8
CRITICAL
VIEW RECORD
CVE-2026-12944
Product identification pending
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-57140
PraisonAI
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-91998
Product identification pending
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-77179
Product identification pending
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-67399
Product identification pending PATCH
Reporter: SUPPORT
9.3
CRITICAL
VIEW RECORD
CVE-2026-45052
OpenAM PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-46619
OpenAM PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-89308
TrxTimeATTENDANCE
Reporter: A6D3DC9E-0591-4A13-BCE7-0F5B31FF6158
9.3
CRITICAL
VIEW RECORD
CVE-2026-91995
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-39919
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2023-54398
U8 Cloud
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2024-58385
U8 CRM
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-89026
Issabel Framework
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-53459
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-45051
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-62263
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-46495
OpenDJ PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-91949
FreeRDP PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-91988
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-69204
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2026-50006
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-53713
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-90711
Product identification pending PATCH
Reporter: CE714D77-ADD3-4F53-AFF5-83D477B104BB
9.1
CRITICAL
VIEW RECORD
CVE-2026-48717
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-52824
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-55158
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-63696
Product identification pending PATCH
Reporter: SECURITY_ALERT
9.1
CRITICAL
VIEW RECORD
CVE-2026-46488
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-89022
Product identification pending PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-61549
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9
CRITICAL
VIEW RECORD
CVE-2023-54397
Product identification pending PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2024-14029
Product identification pending PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2026-77866
safeurl
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9
CRITICAL
VIEW RECORD
CVE-2026-77972
safeurl
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
9
CRITICAL
VIEW RECORD
CVE-2026-91931
Product identification pending PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2026-91932
Product identification pending PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2026-16428
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-16466
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-16673
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-13293
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-43686
Product identification pending PATCH
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-43692
macos PATCH
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-65374
Product identification pending PATCH
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-65390
Product identification pending PATCH
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-65391
Product identification pending PATCH
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-57133
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-57136
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-57137
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-14805
Consulting – Business, Finance WordPress Theme
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92006
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92007
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92008
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92009
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92010
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92011
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92012
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92013
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92014
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92015
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92017
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92020
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92033
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92043
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92047
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92052
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92053
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92054
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92055
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92062
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-92073
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-16140
phosphor-net-ipmid
Reporter: 44488DAB-36DB-4358-99F9-BC116477F914
8.8
HIGH
VIEW RECORD
CVE-2026-19780
Koha
Reporter: ZDI-DISCLOSURES
8.8
HIGH
VIEW RECORD
CVE-2026-59160
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-12728
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-40058
Falcon sensor for Windows PATCH
Reporter: 13DDCD98-6F4A-40A8-8E24-29CA0AEE4661
8.8
HIGH
VIEW RECORD
CVE-2026-44300
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-52484
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-82028
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-68489
Product identification pending PATCH
Reporter: SUPPORT
8.7
HIGH
VIEW RECORD
CVE-2026-91144
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-91200
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.