Description
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the complete original string to child_process.exec(). A string that starts with an allowed read-only command can append a second non-allowlisted command through shell syntax, allowing arbitrary command execution with the PraisonAI process privileges. This issue is fixed in version 1.7.2.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw in PraisonAI’s shell helper permits an attacker to construct a command that starts with an allowed read‑only command and appends a second, non‑allowlisted instruction using shell syntax. Because the helper validates only the first token against a safe‑command list before passing the entire unvalidated string to child_process.exec(), the process can execute any command given to the shell() function. This results in remote code execution with the privileges of the PraisonAI process. The weakness is a combination of insecure command validation (CWE‑693, CWE‑78) and insufficient input filtering (CWE‑863).

Affected Systems

MervinPraison’s PraisonAI product is affected in all releases from version 1.5.1 through 1.7.1 inclusive. The vulnerability is fixed in version 1.7.2 and later versions, so any deployment newer than 1.7.2 is not vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1 % suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker who can supply input to the shell() helper—either locally or via an exposed interface—can trigger arbitrary command execution. Since child_process.exec is used, the exploit achieves full code execution with the process’s privileges, potentially compromising the host system.

Generated by OpenCVE AI on September 17, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 1.7.2 or later to apply the official fix.
  • If an upgrade is not immediately possible, run the PraisonAI process with the minimum required privileges and isolate it from critical system resources to limit any damage if an attacker succeeds.
  • As a temporary workaround, constrain the shell helper to validate the entire command string against the safe‑command allowlist and remove or restrict shell‑chaining syntax so that child_process.exec is invoked only with strictly whitelisted commands.

Generated by OpenCVE AI on September 17, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5jv7-2mjm-h6qj npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the complete original string to child_process.exec(). A string that starts with an allowed read-only command can append a second non-allowlisted command through shell syntax, allowing arbitrary command execution with the PraisonAI process privileges. This issue is fixed in version 1.7.2.
Title PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
Weaknesses CWE-693
CWE-78
CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:44:02.031Z

Reserved: 2026-06-24T00:33:17.708Z

Link: CVE-2026-57133

cve-icon Vulnrichment

Updated: 2026-09-16T17:43:41.340Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:10.437

Modified: 2026-09-16T18:17:09.980

Link: CVE-2026-57133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-863

    Incorrect Authorization