Executive brief
PraisonAI, an AI agent framework, contains a security flaw in how it restricts system commands. An attacker can bypass these restrictions to read sensitive files, delete data, or run unauthorized programs by using the 'find' command's built-in execution features. This could lead to a full compromise of the system hosting the AI agent.
Technical details
A vulnerability in PraisonAI's shell command hardening allows for an allowlist bypass. While the software filters shell metacharacters and uses non-shell execution (spawn/subprocess.Popen with shell=false), the 'find' utility remains in the safe command allowlist. Attackers can use find's internal actions like -exec, -execdir, and -delete to execute arbitrary binaries or manipulate files. Because these actions are interpreted by the find binary itself rather than the shell, they bypass regex-based metacharacter filters and path restrictions. The issue affects both the TypeScript and Python implementations of the shell and sandbox executors. Users should upgrade to version 4.6.78 or later.
Affected products
- MervinPraison PraisonAI < 4.6.78
Timeline
- 2026-06-25: advisory: GitHub Security Advisory published by vendor
- 2026-07-10: disclosed: NVD publication date