GHSA-65c8-r727-2mpjHigh· 7.5▾ TwilightDuplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-5r6c-gj4g-r697. This link is maintained to preserve external references.
PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.
PraisonAI <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60085HighPraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
GHSA-3wrm-pm5v-8vq8Medium· 7.2Duplicate Advisory: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
CVE-2026-60091High· 7.2PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
GHSA-5866-9272-qcfvMedium· 7.3Duplicate Advisory: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
CVE-2026-61427High· 7.3PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls