Praisonai · Praisonai · CVE-2026-61434
**Name of the Vulnerable Software and Affected Versions**
PraisonAI versions prior to 4.6.78
**Description**
An allowlist bypass exists in shell command execution. Attackers can execute restricted commands by utilizing the built-in `-exec`, `-execdir`, and `-delete` actions of the `find` command. This allows for reading blocked files, deleting files, or executing binaries not present on the allowlist by bypassing shell metacharacter filters.
**Recommendations**
Update PraisonAI to version 4.6.78 or later.