OVERVIEW CVE-2026-40153 affects PraisonAIAgents prior to version 1.5.128 and involves improper environment variable expansion in the execute_command function. The vulnerability stems from the shell_tools.py module calling os.path.expandvars() on all command arguments while simultaneously using shell=False, which creates a discrepancy between what users approve and what actually executes. This design flaw enables attackers to exfiltrate sensitive environment variables including database credentials, API keys, and cloud access tokens. SEVERITY The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector requiring minimal complexity and user interaction. The primary impact is confidentiality compromise, as attackers can access high-sensitivity secrets stored in environment variables. The approval system exacerbates the risk by displaying unexpanded variable references to human reviewers, masking the true nature of executed commands and creating a false sense of security during the approval workflow. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, and the vulnerability does not appear on the Known Exploited Vulnerabilities catalog. The EPSS score of 0.00033 indicates very low predicted exploitation probability relative to other CVEs. Community attention remains minimal, with no publicly disclosed exploit code available. Organizations running PraisonAIAgents should prioritize upgrading to version 1.5.128 as part of standard patch management procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.128CPE matchmatch criteria | cpe:2.3:a:praison:praisonaiagents:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.