CriticalVulnerabilityLLM-specific
GHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
- Identifiers
- CVE-2026-61445GHSA-9mp3-24cc-77mg
- Published
- Record updated
Summary
The AICoder UI component in PraisonAI exposes write_to_file and execute_command tools to the LLM without path validation or command sanitization. Through prompt injection in the chat interface, an attacker can write to arbitrary filesystem locations, such as /root/.ssh/authorized_keys or /etc/crontab, and execute arbitrary shell commands. Docker containers run as root, which increases the impact.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database