Executive brief
PraisonAI is an AI agent framework that includes a safety feature requiring human approval before an agent executes risky commands. A vulnerability in the approval dashboard allows an attacker to embed malicious code within a tool's arguments. If a human administrator views the approval request, this code can automatically approve the dangerous command without the administrator's consent, potentially allowing the attacker to execute arbitrary code or delete files on the system.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the `HTTPApproval` backend of PraisonAI. The `_build_html()` function in `src/praisonai/praisonai/bots/_http_approval.py` uses raw f-string interpolation to render tool arguments, names, and risk levels into the dashboard without HTML escaping. An attacker who can influence an agent's task or prompt can inject a JavaScript payload into a tool argument. When an administrator views the pending request, the script executes in the dashboard's origin and performs a POST request to the `/approve/{request_id}/decide` endpoint to self-approve the malicious tool call. This allows for the execution of dangerous tools like `execute_command` or `delete_file` with the privileges of the PraisonAI process. The vulnerability is patched in version 4.6.59.
Affected products
- MervinPraison PraisonAI >= 4.5.2, <= 4.6.58
Timeline
- 2026-06-17: patched: Version 4.6.59 released
- 2026-06-18: advisory