Junglewise Threat Intelligence

MervinPraison PraisonAI shell allowlist bypass in utility-tools

Severity: high · CVSS 8.8 · Published 2026-06-18

Vendors: MervinPraison.

Executive brief

PraisonAI is an AI agent framework that includes a utility for running safe, read-only shell commands. A security flaw allows attackers to bypass the safety checks by chaining multiple commands together using special characters like semicolons. This could allow an attacker to execute unauthorized commands on the underlying system, potentially leading to data theft or full system compromise.

Technical details

The `shell()` helper in `dist/tools/utility-tools.js` implements an allowlist of 'safe' commands (e.g., ls, cat, grep). However, the validation logic only checks the first whitespace-delimited token of the input string while passing the entire unsanitized string to Node's `child_process.exec()`. Because `exec()` invokes a shell, an attacker can provide a command like 'echo ok; malicious_command' to bypass the check. This allows for arbitrary command execution with the privileges of the PraisonAI process. The vulnerability is present in versions 1.5.1 through 1.7.1 and is fixed in version 1.7.2.

Affected products

  • MervinPraison praisonai >= 1.5.1, <= 1.7.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: patched: Fixed in version 1.7.2
  • 2026-06-18: advisory

References