{"data":{"id":"3c375817-eeed-4d79-b2e8-33c05585d168","title":"GHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in action","summary":"PraisonAI's shell command hardening, shipped in npm 1.7.2 and Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj and GHSA-vjv9-7m7j-h833, can be bypassed through find's built-in -exec action. The fix blocks shell metacharacters and uses spawn() with shell: false, but find stays in the safe command allowlist, and the batch terminator + replaces the blocked ; so commands run without metacharacters. The same gap exists in four implementations, including the TS shell() tool and the Python safe_shell module, and a find -execdir payload reads /etc/passwd while evading the SandboxExecutor path check.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-cv3g-hj65-pcfh","publishedAt":"2026-10-08T22:00:55.000Z","cveId":"CVE-2026-61434","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["praisonai@<= 4.6.77 (fixed: 4.6.78)"],"affectedPackageNames":["praisonai"],"affectedVendors":[],"affectedVendorsRaw":["PraisonAI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00877,"epssCheckedAt":"2026-10-10T03:00:40.088Z","kevDateAdded":null,"advisoryAliases":["GHSA-cv3g-hj65-pcfh"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T22:00:55.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}