CVE-2026-39891 | MervinPraison PraisonAI up to 4.5.114 File Content create_agent_centric_tools code injection (GHSA-hwg5-x759-7wjg)
A vulnerability was found in MervinPraison PraisonAI up to 4.5.114. It has been classified as critical. Affected is the function create_agent_centric_tools of the component File Content Handler. Performing a manipulation results in code injection.
This vulnerability is reported as CVE-2026-39891. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.