Executive brief
PraisonAIAgents is a framework for building and managing AI agents. A vulnerability in its memory hooks component allows an attacker to execute arbitrary system commands on the host machine. This can occur if an attacker can modify a configuration file or influence agent prompts, potentially leading to full system takeover, data theft, or persistent backdoors in automated environments.
Technical details
The vulnerability exists in `src/praisonai-agents/praisonaiagents/memory/hooks.py` where user-controlled command strings from `hooks.json` are passed directly to `subprocess.run()` with `shell=True`. The application lacks any sanitization or validation (such as `shlex.quote()` or allowlisting) for these commands. Attackers can exploit this via two surfaces: directly through hook event configurations or indirectly via prompt injection if an agent has file-write access to the workspace, allowing it to overwrite `.praisonai/hooks.json`. This enables arbitrary command execution with the privileges of the agent process and allows for persistent backdoors that trigger during standard lifecycle events like `BEFORE_TOOL` or `AFTER_TOOL`. A fix is available in version 1.5.128.
Affected products
- MervinPraison praisonaiagents <= 1.5.126
Timeline
- 2026-04-09: disclosed
- 2026-04-10: advisory: GHSA-v7px-3835-7gjx published
- 2026-04-10: patched: Fixed in version 1.5.128