Impact
PraisonAI’s Jobs API allows an unauthenticated party to POST a job definition that includes an agent YAML payload. The approve field can be set to mark the execute_command action as YAML‑approved, thereby bypassing the required approval check that normally protects critical tools. This chain enables the configured language‑model agent to execute arbitrary operating‑system commands without credentials or operator intervention. The flaw is a severe authentication bypass combined with improper input validation (CWE‑306 and CWE‑863) and can lead to complete system compromise.
Affected Systems
The vulnerability affects all installations of PraisonAI version 4.6.59 and earlier and PraisonAI Agents 1.6.59 and earlier. The affected vendors are MervinPraison for both the main PraisonAI application and the agents component. Users should verify the version of both components and consider upgrading to a fixed release.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity level. A publicly exposed network edge can reach the vulnerable /api/v1/runs endpoint, and because the request is unauthenticated, an attacker can craft a payload from any host. The EPSS score is not available, so the current probability of exploitation is unknown, but the lack of authentication makes exploitation highly feasible. The vulnerability is not yet listed in the CISA KEV catalog, yet its severity and the complete lack of input validation make it a high‑priority target for adversaries.
OpenCVE Enrichment
Github GHSA