A vulnerability has been found in MervinPraison PraisonAI up to 4.5.120 and classified as critical. The affected element is the function execute_command. The manipulation leads to os command injection.

This vulnerability is documented as CVE-2026-40088. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.