Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2026-47391

PraisonAI’s first‑party A2A server example before version 4.6.40 exposes an unauthenticated JSON‑RPC endpoint that allows remote code execution via a Python eval() tool. The server listens on all interfaces, so any internet‑connected attacker can trigger the vulnerability. The issue is fixed in version 4.6.40.

publishedJul 21, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
52th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 20, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users of PraisonAI’s multi‑agent teams system running any version earlier than 4.6.40 that follows the default A2A example or similar unauthenticated deployments with unsafe tools.

02

Real-world impact

An attacker can send a crafted request to the /a2a endpoint, causing the server to execute arbitrary Python code. This can lead to full compromise of the server, including data theft, modification, or creation of files on the host.

03

Why this severity

The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network without authentication, with no user interaction required, and provides complete confidentiality, integrity, and availability impact.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade PraisonAI to version 4.6.40 or later.
  2. 02Restart the PraisonAI service to ensure the new version is running.

NVD-referenced vendor advisory

05

Timeline

  1. Jul 21, 2026 · 11d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 11d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →