Executive brief
PraisonAI, an AI agent framework, contains a critical security flaw in its AICoder component. An attacker can use the chat interface to trick the AI into writing malicious files anywhere on the system or executing dangerous commands. Because the software often runs with high privileges (root) in Docker environments, this could allow a complete takeover of the server and access to all stored data.
Technical details
The AICoder component in PraisonAI fails to perform path validation and command sanitization when processing LLM tool calls for 'write_to_file' and 'execute_command'. Specifically, the 'write_to_file' function uses os.path.join in a way that allows absolute paths to override the intended working directory, enabling path traversal (CWE-22). The 'execute_command' function passes LLM-generated strings directly to a subprocess without sanitization, leading to OS command injection (CWE-78). An authenticated user can exploit these by providing malicious prompts that trigger the LLM to call these tools with attacker-controlled arguments. The impact is heightened in Docker deployments where the application typically runs as the root user.
Affected products
- MervinPraison PraisonAI < 4.6.78
Timeline
- 2026-06-25: advisory: GitHub Security Advisory published
- 2026-07-11: disclosed: CVE published to NVD