Executive brief
PraisonAI is an AI agent framework that can be configured to manage emails. A vulnerability in its email tool allows an attacker to manipulate the AI's prompts to execute unauthorized commands on the connected email server. This could lead to the theft of sensitive emails from private folders, unauthorized modification of messages, or the permanent deletion of the entire mailbox.
Technical details
An IMAP command injection vulnerability exists in the `email_tools.py` component of PraisonAI. The software constructs IMAP SEARCH commands by directly interpolating LLM-controlled parameters (such as sender address, subject, and query) into protocol strings using f-strings with double-quote delimiters. Because these inputs are not sanitized, an attacker can provide crafted strings containing double-quotes to break out of the intended command context and inject arbitrary IMAP commands. This can be achieved via prompt injection against an agent configured with IMAP credentials. Successful exploitation allows for unauthorized email exfiltration, folder enumeration, and destructive operations like email deletion. The issue is addressed in version 1.6.59.
Affected products
- MervinPraison praisonaiagents <= 1.6.48
Timeline
- 2026-06-17: disclosed
- 2026-06-18: advisory: GitHub Advisory GHSA-c969-5x3p-vq3v published.
- 2026-06-18: patched: Version 1.6.59 released.