---
id: GHSA-r3xw-gcpr-rf26
title: >-
  Duplicate Advisory: PraisonAI: Human-in-the-loop tool approval is cached by
  tool name and silently reused for all subsequent calls with arbitrary
  arguments
summary: >-
  Duplicate Advisory: PraisonAI: Human-in-the-loop tool approval is cached by
  tool name and silently reused for all subsequent calls with arbitrary
  arguments
severity: medium
cvss: 6.1
cwe:
  - CWE-863
vendor: praisonaiagents
product: praisonaiagents
ecosystem: pip
affected:
  - praisonaiagents <= 1.6.77
published: '2026-07-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:43:41Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-r3xw-gcpr-rf26'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-29r9-67vg-qj56
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-60087'
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-before-tool-approval-cache-bypass
  - url: 'https://github.com/advisories/GHSA-r3xw-gcpr-rf26'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-08T16:52:14.780Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-29r9-67vg-qj56. This link is maintained to preserve external references.

### Original Description
PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.

## Affected packages

- `praisonaiagents <= 1.6.77`

## Remediation

Refer to the advisory for the patched release.
