Description
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended criterion and alter IMAP operations when search_emails, reply_email, or archive_email is exposed to an agent with configured email credentials, allowing mailbox data access, modification, deletion, or connection disruption. This issue is fixed in praisonaiagents 1.6.59.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Mailbox Access and Disruption
Action: Immediate Patch
AI Analysis

Impact

PraisonAI’s email module is used to manage mailbox interactions. In releases before 1.6.59 the code fetches LLM‑controlled values for from_addr, subject and query and inserts them directly into a quoted IMAP SEARCH criterion without sanitizing them. An attacker who can influence any of these parameters can inject quotation marks, backslashes, newlines or null bytes to terminate or change the intended search string. This manipulation can cause the IMAP server to execute arbitrary commands, leading to unauthorized mailbox access, data modification or deletion, or even connection disruption.

Affected Systems

The vulnerability is present in MervinPraison’s PraisonAI agents in any release prior to version 1.6.59, such as 1. these earlier versions should upgrade to 1.6.59 or higher to obtain the fix, or otherwise restrict agent exposure to email handling functions.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS indicates a low exploitation probability (<1%), and the issue is not listed in CISA KEV, but the lack of public exploitation data does not diminish the inherent risk. An attacker who can influence the email address, subject or query arguments of search_emails, reply_email or archive_email functions can inject malicious IMAP commands. For agents exposed to external or untrusted inputs, the attack path is straightforward and can provide full mailbox compromise or service disruption, warranting prompt remediation.

Generated by OpenCVE AI on September 21, 2026 at 00:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MervinPraison PraisonAI agents to version 1.6.59 or later to apply the injection fix.
  • Ensure that agents with configured email credentials are not exposed to untrusted or externally controlled inputs; isolate or disable public‑facing email functions if possible.
  • Validate or sanitize all user‑supplied email parameters before they are incorporated into IMAP SEARCH statements to eliminate the injection vector.

Generated by OpenCVE AI on September 21, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c969-5x3p-vq3v PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
History

Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonaiagents
Vendors & Products Mervinpraison
Mervinpraison praisonaiagents

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended criterion and alter IMAP operations when search_emails, reply_email, or archive_email is exposed to an agent with configured email credentials, allowing mailbox data access, modification, deletion, or connection disruption. This issue is fixed in praisonaiagents 1.6.59.
Title PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
Weaknesses CWE-20
CWE-77
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonaiagents
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T14:47:00.197Z

Reserved: 2026-06-24T00:33:17.708Z

Link: CVE-2026-57130

cve-icon Vulnrichment

Updated: 2026-09-14T14:46:52.815Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:06.453

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')