{"id":"GHSA-65c8-r727-2mpj","title":"Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend","summary":"Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend","severity":"high","cvss":7.5,"cwe":["CWE-273"],"vendor":"PraisonAI","product":"PraisonAI","ecosystem":"pip","affected":["PraisonAI <= 4.6.77"],"published":"2026-07-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:58:06Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-65c8-r727-2mpj","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5r6c-gj4g-r697"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60085"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-unenforced-security-policy-in-subprocess-sandbox"},{"url":"https://github.com/advisories/GHSA-65c8-r727-2mpj"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-08T22:11:53.881Z","slug":"GHSA-65c8-r727-2mpj","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-5r6c-gj4g-r697. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.\n\n## Affected packages\n\n- `PraisonAI <= 4.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}