CVE-2026-40111 | MervinPraison PraisonAIAgents up to 1.5.127 Configuration hooks.py subprocess.run os command injection (GHSA-v7px-3835-7gjx)
A vulnerability was found in MervinPraison PraisonAIAgents up to 1.5.127 and classified as critical. This vulnerability affects the function subprocess.run of the file src/praisonai-agents/praisonaiagents/memory/hooks.py of the component Configuration Handler. The manipulation results in os command injection.
This vulnerability is identified as CVE-2026-40111. The attack is only possible with local access. There is not any exploit available.
It is suggested to upgrade the affected component.