CVE-2026-55522
published 2026-08-05CVE-2026-55522: PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include"…
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.15%
4.7th percentile
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw importlib.util.spec_from_file_location() and spec.loader.exec_module() call, without honoring the PRAISONAI_ALLOW_TEMPLATE_TOOLS/PRAISONAI_ALLOW_LOCAL_TOOLS autoload opt-in gates or routing through the centralized safe loader that protects the other tools.py autoload paths. As a result, a workflow that includes an attacker-controlled local recipe directory executes arbitrary module-level Python code during include setup, before any child workflow parsing or model call, and the same sink is reachable through the higher-level praisonai.recipe.run() recipe API. An attacker who can cause a victim process to run a workflow or recipe that includes an untrusted local recipe achieves arbitrary Python code execution as the PraisonAI process user, a variant that bypasses the hardening applied to the previously disclosed automatic tools.py RCE advisory family. This issue has been fixed in version 4.6.58 of praisonai and 1.6.58 of praisonaiagents.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai | — | — |
| mervinpraison | praisonai | >= 3.9.26 < 4.6.58 | 4.6.58 |
| mervinpraison | praisonaiagents | — | — |
| mervinpraison | praisonaiagents | >= 0.12.12 < 1.6.58 | 1.6.58 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
ghsa·2026-08-25
CVE-2026-55522 [HIGH] CWE-94 PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
## Summary
PraisonAI's workflow include implementation implicitly imports and executes an included recipe's `tools.py` file even when the documented `tools.py` autoload opt-in is unset.
This bypasses the hardening added for the prior automatic `tools.py` RCE advisory family. A workflow that includes an untrusted local recipe can execute arbitrary Python module-level code before any model call or child workflow execution.
The same sink is reachable through the higher-level `praisonai.recipe.run()` recipe API when a steps-based recipe workflow includes a local child recipe. The supplementary PoV demonstrates this route without starting a network service or relying on external APIs.
This is dis
VulDB
MervinPraison PraisonAI/praisonaiagents Tool Loader tools.py Workflow._execute_include code injection
vuldb·2026-08-05·CVSS 7.8
CVE-2026-55522 [HIGH] MervinPraison PraisonAI/praisonaiagents Tool Loader tools.py Workflow._execute_include code injection
A vulnerability marked as critical has been reported in MervinPraison PraisonAI and praisonaiagents. This affects the function Workflow._execute_include of the file tools.py of the component Tool Loader. This manipulation causes code injection.
This vulnerability appears as CVE-2026-55522. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-05
Published