GHSA-r3xw-gcpr-rf26Medium· 6.1▾ SunlitDuplicate Advisory: PraisonAI: Human-in-the-loop tool approval is cached by tool name and silently reused for all subsequent calls with arbitrary arguments
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-29r9-67vg-qj56. This link is maintained to preserve external references.
PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.
praisonaiagents <= 1.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60087Medium· 6.1PraisonAI: Human-in-the-loop tool approval is cached by tool name and silently reused for all subsequent calls with arbitrary arguments
CVE-2026-60089MediumPraisonAI: Project config can auto-save agent output outside the project root
GHSA-rrqj-82cc-g6h4Medium· 5.5Duplicate Advisory: PraisonAI: Project config can auto-save agent output outside the project root
CVE-2026-61430High· 8.5PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
GHSA-92x2-g374-gcvxHigh· 8.5Duplicate Advisory: PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
GHSA-q359-rmv4-56fgHigh· 8.4Duplicate Advisory: PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification