A vulnerability has been found in MervinPraison PraisonAI up to 4.5.120 and classified as critical. The affected element is the function
execute_command. The manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-40088. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.