Impact
The flaw in PraisonAI’s shell helper permits an attacker to construct a command that starts with an allowed read‑only command and appends a second, non‑allowlisted instruction using shell syntax. Because the helper validates only the first token against a safe‑command list before passing the entire unvalidated string to child_process.exec(), the process can execute any command given to the shell() function. This results in remote code execution with the privileges of the PraisonAI process. The weakness is a combination of insecure command validation (CWE‑693, CWE‑78) and insufficient input filtering (CWE‑863).
Affected Systems
MervinPraison’s PraisonAI product is affected in all releases from version 1.5.1 through 1.7.1 inclusive. The vulnerability is fixed in version 1.7.2 and later versions, so any deployment newer than 1.7.2 is not vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1 % suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker who can supply input to the shell() helper—either locally or via an exposed interface—can trigger arbitrary command execution. Since child_process.exec is used, the exploit achieves full code execution with the process’s privileges, potentially compromising the host system.
OpenCVE Enrichment
Github GHSA