{"data":{"id":"3f9a9ed0-0129-4079-a09f-218d664e3999","title":"GHSA-c44f-37qr-gw3f: PraisonAI: SkillTools Executes Scripts Without Path Containment Validation","summary":"PraisonAI's SkillTools.run_skill_script() accepts a script_path parameter and executes it via subprocess.run() with no path containment validation, unlike FileTools._validate_path(). An LLM-directed call can therefore run arbitrary scripts from any filesystem location, and the @require_approval decorator can be bypassed via YAML approve: for high-risk tools. Chaining with write_file lets an attacker plant and then execute a script, and because PraisonAI Docker containers run as root, an executed script gains root privileges.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-c44f-37qr-gw3f","publishedAt":"2026-10-08T16:49:23.000Z","cveId":"CVE-2026-61443","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["praisonaiagents@<= 1.6.77 (fixed: 1.6.78)"],"affectedPackageNames":["praisonaiagents"],"affectedVendors":[],"affectedVendorsRaw":["PraisonAI"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00769,"epssCheckedAt":"2026-10-10T03:00:40.530Z","kevDateAdded":null,"advisoryAliases":["GHSA-c44f-37qr-gw3f"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T16:49:23.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0010"]}}