GHSA-cfxv-8fw8-rwpv: praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
Summary
The `ast_grep_rewrite` function in PraisonAI (a library that lets AI agents modify code) can rewrite files on disk without asking for user approval, unlike all its similar sibling functions which have approval gates. An attacker or malicious prompt can use this unprotected function to inject arbitrary code into files, and the function falsely reports 'No changes made' even when files are modified, hiding the attack from the operator.
Vulnerability Details
EPSS: 0.0%
Yes
August 25, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-cfxv-8fw8-rwpv
First tracked: August 25, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%