Executive brief
PraisonAI is an AI agent framework used to automate tasks and workflows. A security vulnerability allows an unauthenticated attacker to remotely execute arbitrary commands on the server hosting the application. This could lead to a complete system takeover, unauthorized access to sensitive data, and disruption of business operations.
Technical details
The vulnerability consists of two chained flaws. First, the `/api/v1/runs` endpoint in the Jobs API (router.py) lacks authentication, allowing any network-reachable user to submit agent jobs. Second, the workflow YAML parser (yaml_parser.py) allows a top-level 'approve' field that populates a ContextVar used by the `@require_approval` decorator. By including 'execute_command' in this field, an attacker can bypass safety checks for dangerous tools. When combined, an attacker can submit a crafted YAML that instructs the LLM to execute arbitrary shell commands via subprocess.Popen without any user interaction or credentials. The issue is fixed in versions 4.6.59 (praisonai) and 1.6.59 (praisonaiagents).
Affected products
- MervinPraison praisonai <= 4.6.48
- MervinPraison praisonaiagents < 1.6.59
Timeline
- 2026-06-17: disclosed
- 2026-06-18: advisory: GitHub Advisory published