CVE-2026-44339 - Vulnerability Analysis
HighCVSS: 8.6Last Updated: May 8, 2026
PraisonAI - Unauthorized Function Invocation
Published: May 8, 2026Updated: May 8, 2026PoC AvailableRemote Exploitable
Overview
PraisonAI < 4.6.37 and praisonaiagents < 1.6.37 contain an unauthorized function invocation vulnerability caused by resolving unresolved tool names against module globals and __main__, letting attackers invoke unintended application callables, exploit requires attacker to influence tool-call names.
Severity & Score
Severity: High
CVSS Score: 8.6
Impact
Attackers can invoke unintended application functions, potentially leading to unauthorized actions or code execution.
Mitigation
Update to praisonai version 4.6.37 and praisonaiagents version 1.6.37 or later.
Related Resources
Details
- CVE ID
- CVE-2026-44339
- Severity
- High
- CVSS Score
- 8.6
- Type
- undefined
- Status
- modified
CWE
- CWE-470
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L