HighVulnerability
GHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in action
- Identifiers
- CVE-2026-61434GHSA-cv3g-hj65-pcfh
- Published
- Record updated
Summary
PraisonAI's shell command hardening, shipped in npm 1.7.2 and Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj and GHSA-vjv9-7m7j-h833, can be bypassed through find's built-in -exec action. The fix blocks shell metacharacters and uses spawn() with shell: false, but find stays in the safe command allowlist, and the batch terminator + replaces the blocked ; so commands run without metacharacters. The same gap exists in four implementations, including the TS shell() tool and the Python safe_shell module, and a find -execdir payload reads /etc/passwd while evading the SandboxExecutor path check.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database
- HighGHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surfaceSimilar attack · GitHub Advisory Database