HighVulnerability
GHSA-c44f-37qr-gw3f: PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
- Identifiers
- CVE-2026-61443GHSA-c44f-37qr-gw3f
- Published
- Record updated
- Affected
- praisonaiagents <= 1.6.77
- Fixed in
- 1.6.78
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.8%
Summary
PraisonAI's SkillTools.run_skill_script() accepts a script_path parameter and executes it via subprocess.run() with no path containment validation, unlike FileTools._validate_path(). An LLM-directed call can therefore run arbitrary scripts from any filesystem location, and the @require_approval decorator can be bypassed via YAML approve: for high-risk tools. Chaining with write_file lets an attacker plant and then execute a script, and because PraisonAI Docker containers run as root, an executed script gains root privileges.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database