Description
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from the CommandValidator only checking the first executable token in a command string while the remaining string is passed to the shell. The flaw is a classic command injection (CWE‑78) combined with improper validation logic (CWE‑693) and a lack of authorization checks (CWE‑863). An attacker who can provide input to the SandboxExecutor can inject shell metacharacters to chain additional commands, causing the PraisonAI process to execute arbitrary code with its own privileges. The result is a high‑impact code execution that can affect the confidentiality, integrity, and availability of the host or any resources the process accesses.

Affected Systems

The issue affects PraisonAI version 1.2.3 through 1.7.1 inclusive. The vendor is MervinPraison. All releases prior to 1.7.2 lack the fix; the fix is embedded in the 1.7.2 release and later. Patching to 1.7.2 or newer removes the vulnerability.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is below 1%, suggesting that current exploitation activity is low, and the vulnerability is not yet listed in the CISA KEV catalog. The available attack vector requires the attacker to supply a crafted command string to the sandbox executor; this can be achieved through any interface that forwards user commands to the system. Successful exploitation would allow arbitrary command execution with the PraisonAI process privileges. Given the high severity and potential impact, administrators should prioritize patching or mitigating the vulnerability.

Generated by OpenCVE AI on September 17, 2026 at 17:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 1.7.2 or newer; the patch corrects the validator and removes the bypass.
  • If an immediate upgrade is not feasible, disable or limit the use of SandboxExecutor and validate all command inputs before passing them to the shell, ensuring only allowed executables are executed without shell chaining.
  • Monitor application logs for suspicious command strings and restrict the privileges of the PraisonAI process to the minimum necessary.

Generated by OpenCVE AI on September 17, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vjv9-7m7j-h833 npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2.
Title PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
Weaknesses CWE-693
CWE-78
CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:40:32.718Z

Reserved: 2026-06-24T00:33:17.708Z

Link: CVE-2026-57136

cve-icon Vulnrichment

Updated: 2026-09-15T12:40:22.447Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:10.883

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-863

    Incorrect Authorization