LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-44339

CVE-2026-44339 - Vulnerability Analysis

HighCVSS: 8.6

Last Updated: May 8, 2026

PraisonAI - Unauthorized Function Invocation

Published: May 8, 2026Updated: May 8, 2026PoC AvailableRemote Exploitable

Overview

PraisonAI < 4.6.37 and praisonaiagents < 1.6.37 contain an unauthorized function invocation vulnerability caused by resolving unresolved tool names against module globals and __main__, letting attackers invoke unintended application callables, exploit requires attacker to influence tool-call names.

Severity & Score

Severity: High
CVSS Score: 8.6

Impact

Attackers can invoke unintended application functions, potentially leading to unauthorized actions or code execution.

Mitigation

Update to praisonai version 4.6.37 and praisonaiagents version 1.6.37 or later.

Details

CVE ID
CVE-2026-44339
Severity
High
CVSS Score
8.6
Type
undefined
Status
modified

CWE

  • CWE-470

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L