Junglewise Threat Intelligence

CVE-2026-40149: PraisonAI unauthenticated allowlist manipulation in tool approval system

CVE-2026-40149 · Severity: high · CVSS 7.9 · Published 2026-04-10

Technologies: praisonai (PyPI). Vendors: MervinPraison, PyPI.

Executive brief

PraisonAI, a framework for managing AI agents, contains a security flaw in its tool approval system. By default, the system allows anyone with local access to modify the list of 'approved' tools without a password. This allows an attacker to force the AI to automatically run dangerous commands, such as deleting files or executing system code, bypassing the safety checks intended to require human approval.

Technical details

An authentication bypass exists in PraisonAI's gateway component due to the `_check_auth()` function returning `None` when `auth_token` is not configured (the default state). An attacker can send a POST request to the `/api/approval/allow-list` endpoint to add arbitrary tool names, such as `shell_exec` or `file_write`, to the `ExecApprovalManager` allowlist. Because the `register()` function in `exec_approval.py` prioritizes the allowlist as a 'fast path' for auto-approval, subsequent agent requests to use these tools will execute immediately without human review. This vulnerability is primarily exploitable by local attackers or via SSRF/CORS-related attacks. The issue is fixed in version 4.5.128.

Affected products

  • MervinPraison PraisonAI < 4.5.128

Timeline

  • 2026-04-09: disclosed
  • 2026-04-10: advisory
  • 2026-04-10: patched: Fixed in version 4.5.128

References

Related threats