PraisonAI flaw lets agents run arbitrary shell commands via forced auto-approval
PraisonAI versions before 4.5.128 hardcoded approval_mode to "auto" in UI modules, overriding the PRAISON_APPROVAL_MODE administrator setting. Authenticated users could instruct the LLM agent to run arbitrary shell commands through subprocess.run with shell=True, bypassing the manual approval gate and command sanitization blocklists.
Disclosed 18 June 2026 · Record updated 13 September 2026
Impact
Authenticated attackers could achieve arbitrary shell command execution on hosts running affected PraisonAI versions.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-56075
