PT-2026-50805 · Praisonai · Praisonai

·

CVE-2026-56074

·

Published

2026-04-10

·

Updated

2026-07-13

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 1.5.128
Description The software caches tool approval decisions based solely on the tool name rather than the invocation arguments. This allows subsequent calls to the execute command() function to bypass approval prompts. An attacker can obtain initial approval for a benign command and then silently exfiltrate API keys and credentials using subsequent shell commands without user consent.
Recommendations Update to version 1.5.128 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56074
GHSA-FFP3-3562-8CV3
GHSA-X44P-GG67-52FC
PYSEC-2026-2946

Affected Products

Praisonai