RuleId: CVE-2026-40111
RuleDesc: CVE context for keyword 'PraisonAI' // CWE info: CWE-78 (OS Command Injection)

Vuln Description:
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in
praisonaiagents passes a user-controlled command string directly to subprocess.run() with
shell=True at src/praisonai-agents/praisonaiagents/memory/hooks.py. No sanitization is performed
and shell metacharacters are interpreted by /bin/sh before the intended command executes. Two
independent attack surfaces exist. The first is via pre_run_command and post_run_command hook
event types registered through the hooks configuration. The second and more severe surface is
the .praisonai/hooks.json lifecycle configuration, where hooks registered for events such as
BEFORE_TOOL and AFTER_TOOL fire automatically during agent operation. An agent that gains file-
write access through prompt injection can overwrite .praisonai/hooks.json and have its payload
execute silently at every subsequent lifecycle event without further user interaction. This
vulnerability is fixed in 1.5.128.

Metadata:
- Repository hint: https://github.com/MervinPraison/PraisonAI
- Published at: 2026-04-09T22:16:34.560
- Severity: HIGH (score=8.8)
- Affected summary: praison:praisonaiagents <1.5.128

Related Files:
Use CT-graph history, commit metadata, and referenced URLs to identify the exact files,
functions, or symbols that introduced and later fixed this vulnerability in the target repository.

Reference URLs (from CVE dataset):
- [01] https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-v7px-3835-7gjx
- [02] https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-v7px-3835-7gjx