PT-2026-50805 · Praisonai · Praisonai
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 1.5.128
Description
The software caches tool approval decisions based solely on the tool name rather than the invocation arguments. This allows subsequent calls to the
execute command() function to bypass approval prompts. An attacker can obtain initial approval for a benign command and then silently exfiltrate API keys and credentials using subsequent shell commands without user consent.Recommendations
Update to version 1.5.128 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai