CVE-2026-57136 | MervinPraison PraisonAI up to 1.7.1 SandboxExecutor sandbox-executor.ts CommandValidator os command injection

SecurityVulns

A vulnerability described as critical has been identified in MervinPraison PraisonAI up to 1.7.1. Affected by this issue is the function CommandValidator of the file src/praisonai-ts/src/cli/features/sandbox-executor.ts of the component SandboxExecutor. Such manipulation leads to os command injection.

This vulnerability is listed as CVE-2026-57136. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More