Executive brief
PraisonAI is an AI agent framework that includes a utility for running safe, read-only shell commands. A security flaw allows attackers to bypass the safety checks by chaining multiple commands together using special characters like semicolons. This could allow an attacker to execute unauthorized commands on the underlying system, potentially leading to data theft or full system compromise.
Technical details
The `shell()` helper in `dist/tools/utility-tools.js` implements an allowlist of 'safe' commands (e.g., ls, cat, grep). However, the validation logic only checks the first whitespace-delimited token of the input string while passing the entire unsanitized string to Node's `child_process.exec()`. Because `exec()` invokes a shell, an attacker can provide a command like 'echo ok; malicious_command' to bypass the check. This allows for arbitrary command execution with the privileges of the PraisonAI process. The vulnerability is present in versions 1.5.1 through 1.7.1 and is fixed in version 1.7.2.
Affected products
- MervinPraison praisonai >= 1.5.1, <= 1.7.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: patched: Fixed in version 1.7.2
- 2026-06-18: advisory