Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐍 PyPI

GHSA-vc46-vw85-3wvm

CRITICAL

GHSA-vc46-vw85-3wvm is a critical-severity (CVSS 9.8) OS Command Injection vulnerability in praisonaiagents. O3 Security confirms whether GHSA-vc46-vw85-3wvm is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.

PraisonAI has critical RCE via `type: job` workflow YAML

Also known asCVE-2026-40288PYSEC-2026-477PYSEC-2026-488
Published
Apr 10, 2026
Updated
Jun 29, 2026
Affected
2 pkgs
Patched
2 / 2
Exploits
None indexed

Blast Radius

2 pkgs affected
🐍praisonaiagents🐍praisonai

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.

Description

praisonai workflow run <file.yaml> loads untrusted YAML and if type: job executes steps through JobWorkflowExecutor in job_workflow.py.

This supports:

  • run: → shell command execution via subprocess.run()
  • script: → inline Python execution via exec()
  • python: → arbitrary Python script execution

A malicious YAML file can execute arbitrary host commands.

Affected Code

  • workflow.py → action_run()
  • job_workflow.py → _exec_shell(), _exec_inline_python(), _exec_python_script()

PoC

Create exploit.yaml:

type: job
name: exploit
steps:
  - name: write-file
    run: python -c "open('pwned.txt','w').write('owned')"

Run:

praisonai workflow run exploit.yaml

Reproduction Steps

  1. Save the YAML above as exploit.yaml.
  2. Execute praisonai workflow run exploit.yaml.
  3. Confirm pwned.txt appears in the working directory.

Impact

Remote or local attacker-supplied workflow YAML can execute arbitrary host commands and code, enabling full system compromise in CI or shared deployment contexts.

Reporter: Lakshmikanthan K (letchupkt)

Affected Packages

2 total 2 fixed
EcosystemPackageVulnerable rangeFix
🐍PyPIpraisonaiagentsall versions1.5.140
🐍PyPIpraisonaiall versions4.5.139

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for praisonaiagents. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Fix

    Update praisonaiagents to 1.5.140 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-vc46-vw85-3wvm is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether GHSA-vc46-vw85-3wvm is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to GHSA-vc46-vw85-3wvm. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

`praisonai workflow run <file.yaml>` loads untrusted YAML and if `type: job` executes steps through `JobWorkflowExecutor` in job_workflow.py. This supports: - `run:` → shell command execution via `subprocess.run()` - `script:` → inline Python execution via `exec()` - `python:` → arbitrary Python script execution A malicious YAML file can execute arbitrary host commands. ### Affected Code - workflow.py → `action_run()` - job_workflow.py → `_exec_shell()`, `_exec_inline_python()`, `_exec_python_script()` ### PoC Create `exploit.yaml`: ```yaml type: job name: exploit steps: - name: write-f
O3 Security · Impact-Aware SCA

Is GHSA-vc46-vw85-3wvm in your dependencies?

O3 detects GHSA-vc46-vw85-3wvm across PyPI dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.