<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T14:22:54.616288+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291134</id>
    <title>EUVD-2026-291134</title>
    <updated>2026-10-06T14:22:54.714291+00:00</updated>
    <content>EUVD-2026-291134</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40287</id>
    <title>fkie_cve-2026-40287</title>
    <updated>2026-10-06T14:22:54.714327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py (_load_local_tools()), and CLI tool-loading paths blindly import ./tools.py at startup without any validation, sandboxing, or user confirmation. An attacker who can place a malicious tools.py in the directory where PraisonAI is launched (such as through a shared project, cloned repository, or writable workspace) achieves immediate arbitrary Python code execution in the host environment. This compromises the full PraisonAI process, the host system, and any connected data or credentials. This issue has been fixed in version 4.5.139.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g985-wjh9-qxxc</id>
    <title>GHSA-g985-wjh9-qxxc — PraisonAI Vulnerable to RCE via Automatic tools.py Import</title>
    <updated>2026-10-06T14:22:54.714363+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonaiagents, PyPI: PraisonAI</p>
<p>PraisonAI automatically imports `./tools.py` from the current working directory when launching certain components. This includes call.py, tool_resolver.py, and CLI tool-loading paths.</p>
<p>A malicious tools.py placed in the process working directory is executed immediately, allowing arbitrary Python code execution in the host environment.</p>
<p>### Affected Code
- call.py → `import_tools_from_file()`
- tool_resolver.py → `_load_local_tools()`
- tools.py → local tool import flow
-</p>
<p>### PoC
Create tools.py in the directory where PraisonAI is launched:</p>
<p>```python
# tools.py
import os
os.system("echo pwned &gt; /tmp/pwned.txt")
```</p>
<p>Run any PraisonAI component that loads local tools, for example:</p>
<p>```bash
praisonai workflow run safe.yaml
```</p>
<p>### Reproduction Steps
1. Create a malicious tools.py in the current working directory.
2. Start PraisonAI or invoke a CLI command that loads local tools.
3. Verify that `/tmp/pwned.txt` or the malicious command output exists.</p>
<p>### Impact
An attacker who can place or influence tools.py in the working directory can execute arbitrary code in the PraisonAI process, compromising the host and any connected data.</p>
<p>**Reporter:** Lakshmikanthan K (letchupkt)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g985-wjh9-qxxc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2914</id>
    <title>PYSEC-2026-2914 — PraisonAI Vulnerable to RCE via Automatic tools.py Import</title>
    <updated>2026-10-06T14:22:54.714408+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>PraisonAI automatically imports `./tools.py` from the current working directory when launching certain components. This includes call.py, tool_resolver.py, and CLI tool-loading paths.</p>
<p>A malicious tools.py placed in the process working directory is executed immediately, allowing arbitrary Python code execution in the host environment.</p>
<p>### Affected Code
- call.py → `import_tools_from_file()`
- tool_resolver.py → `_load_local_tools()`
- tools.py → local tool import flow
-</p>
<p>### PoC
Create tools.py in the directory where PraisonAI is launched:</p>
<p>```python
# tools.py
import os
os.system("echo pwned &gt; /tmp/pwned.txt")
```</p>
<p>Run any PraisonAI component that loads local tools, for example:</p>
<p>```bash
praisonai workflow run safe.yaml
```</p>
<p>### Reproduction Steps
1. Create a malicious tools.py in the current working directory.
2. Start PraisonAI or invoke a CLI command that loads local tools.
3. Verify that `/tmp/pwned.txt` or the malicious command output exists.</p>
<p>### Impact
An attacker who can place or influence tools.py in the working directory can execute arbitrary code in the PraisonAI process, compromising the host and any connected data.</p>
<p>**Reporter:** Lakshmikanthan K (letchupkt)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2914"/>
  </entry>
</feed>
