Executive brief
PraisonAIAgents is a framework for building AI agent workflows. A security flaw in its shell execution tool allows an attacker to trick the system into revealing sensitive information like database passwords and API keys stored in environment variables. This is particularly dangerous because the system's approval screen hides the fact that these secrets are being accessed, making it easy for a user to unknowingly authorize a malicious command.
Technical details
The `execute_command` function in `shell_tools.py` uses `os.path.expandvars()` on command arguments before passing them to `subprocess.Popen`. While the system uses `shell=False` to prevent shell injection, the manual expansion of environment variables allows an attacker (potentially via prompt injection) to include references like `$DATABASE_URL` which are resolved to their literal values before execution. Furthermore, the human-in-the-loop approval system displays the unexpanded command string, leading to a 'deceptive approval' where a reviewer sees a variable name but the system executes the sensitive value. This vulnerability is fixed in version 1.5.128.
Affected products
- MervinPraison praisonaiagents < 1.5.128
Timeline
- 2026-04-09: disclosed
- 2026-04-10: advisory
- 2026-04-10: patched: Fixed in version 1.5.128