CVE-2026-44336
critical
CVSS v3
9.6
CVSS v2
—
VIR risk
9.6
Description
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
Predictions
Exploit likelihood
96%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security-advisories@github.com — https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9mqq-jqxf-grvw
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| praison | praisonai | {"endExcluding":"4.6.34"} | 4.6.34 |
References
CWEs
CWE-20 CWE-22 CWE-94 CWE-829 CWE-913
Verify integrity in audit chain (admin only). AS-IS.