Executive brief
PraisonAI, a framework for managing AI agents, contains a security flaw in its tool approval system. By default, the system allows anyone with local access to modify the list of 'approved' tools without a password. This allows an attacker to force the AI to automatically run dangerous commands, such as deleting files or executing system code, bypassing the safety checks intended to require human approval.
Technical details
An authentication bypass exists in PraisonAI's gateway component due to the `_check_auth()` function returning `None` when `auth_token` is not configured (the default state). An attacker can send a POST request to the `/api/approval/allow-list` endpoint to add arbitrary tool names, such as `shell_exec` or `file_write`, to the `ExecApprovalManager` allowlist. Because the `register()` function in `exec_approval.py` prioritizes the allowlist as a 'fast path' for auto-approval, subsequent agent requests to use these tools will execute immediately without human review. This vulnerability is primarily exploitable by local attackers or via SSRF/CORS-related attacks. The issue is fixed in version 4.5.128.
Affected products
- MervinPraison PraisonAI < 4.5.128
Timeline
- 2026-04-09: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched: Fixed in version 4.5.128