GHSA-x44p-gg67-52fcMedium· 5.5▾ SunlitDuplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-ffp3-3562-8cv3. This link is maintained to preserve external references.
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.
praisonai < 4.5.128Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56839High· 7.3PraisonAI is a multi-agent teams system
CVE-2026-57125Critical· 9.8PraisonAI is a multi-agent teams system
GHSA-8579-rgg5-ph2mHigh· 8.8PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
GHSA-qvpf-j64c-jmhrHigh· 8.3PraisonAI Slack app_mention bypasses configured user/channel authorization
GHSA-v847-hxxw-3pxgHigh· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-w6h2-fr4q-xvxvHigh· 8.8PraisonAI: Compute-bridged file tools allow shell command injection