GHSA-wj29-gm8v-33x8Critical· 9.9▾ MidnightDuplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-9mp3-24cc-77mg. This link is maintained to preserve external references.
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls
GHSA-wgvq-3jxh-4qg7Medium· 5.5Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts
GHSA-w37c-cq55-frjpMedium· 5.5Duplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-61431Medium· 5.5PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-55540High· 7.1PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
CVE-2026-57119High· 7.5PraisonAI is a multi-agent teams system