Impact
PraisonAI’s email module is used to manage mailbox interactions. In releases before 1.6.59 the code fetches LLM‑controlled values for from_addr, subject and query and inserts them directly into a quoted IMAP SEARCH criterion without sanitizing them. An attacker who can influence any of these parameters can inject quotation marks, backslashes, newlines or null bytes to terminate or change the intended search string. This manipulation can cause the IMAP server to execute arbitrary commands, leading to unauthorized mailbox access, data modification or deletion, or even connection disruption.
Affected Systems
The vulnerability is present in MervinPraison’s PraisonAI agents in any release prior to version 1.6.59, such as 1. these earlier versions should upgrade to 1.6.59 or higher to obtain the fix, or otherwise restrict agent exposure to email handling functions.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS indicates a low exploitation probability (<1%), and the issue is not listed in CISA KEV, but the lack of public exploitation data does not diminish the inherent risk. An attacker who can influence the email address, subject or query arguments of search_emails, reply_email or archive_email functions can inject malicious IMAP commands. For agents exposed to external or untrusted inputs, the attack path is straightforward and can provide full mailbox compromise or service disruption, warranting prompt remediation.
OpenCVE Enrichment
Github GHSA