Executive brief
PraisonAI is a framework for managing AI agents. A vulnerability in its file-handling tools allows an attacker to execute unauthorized commands on the underlying server or within a Docker container. This could lead to a full system takeover, data theft, or disruption of services by bypassing security restrictions intended to limit the agent's capabilities.
Technical details
An OS command injection vulnerability exists in PraisonAI's `LocalManagedAgent` and `SandboxedAgent` when compute bridging is enabled. The `_bridge_file_tool()` function in `managed_local.py` constructs shell command strings (e.g., using `cat` or `ls`) by f-string interpolation of raw, unvalidated file path arguments. These strings are then executed via `asyncio.create_subprocess_shell` or `sh -c` in Docker environments. An attacker who can influence file-tool arguments—such as through prompt injection or a chat interface—can use shell metacharacters to escape the quoted path and execute arbitrary commands. This allows an attacker to bypass tool-approval registries that normally classify file operations as low-risk compared to explicit command execution tools. The issue is fixed in version 4.6.59.
Affected products
- MervinPraison praisonai >= 4.6.10, <= 4.6.58
Timeline
- 2026-06-17: disclosed
- 2026-06-18: advisory: GitHub Advisory GHSA-w6h2-fr4q-xvxv published
- 2026-06-18: patched: Fixed in version 4.6.59