GHSA-wrw8-384c-cg76High· 8.8▾ TwilightDuplicate Advisory: PraisonAI: Shell command allowlist bypass via find -exec built-in action
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-cv3g-hj65-pcfh. This link is maintained to preserve external references.
PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters.
PraisonAI <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61434High· 8.8PraisonAI: Shell command allowlist bypass via find -exec built-in action
CVE-2026-57124Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-61445Critical· 9.9PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls
GHSA-v847-hxxw-3pxgHigh· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-w6h2-fr4q-xvxvHigh· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
GHSA-p75f-6fp4-p57wCritical· 9.8PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai