Impact
This vulnerability arises from the CommandValidator only checking the first executable token in a command string while the remaining string is passed to the shell. The flaw is a classic command injection (CWE‑78) combined with improper validation logic (CWE‑693) and a lack of authorization checks (CWE‑863). An attacker who can provide input to the SandboxExecutor can inject shell metacharacters to chain additional commands, causing the PraisonAI process to execute arbitrary code with its own privileges. The result is a high‑impact code execution that can affect the confidentiality, integrity, and availability of the host or any resources the process accesses.
Affected Systems
The issue affects PraisonAI version 1.2.3 through 1.7.1 inclusive. The vendor is MervinPraison. All releases prior to 1.7.2 lack the fix; the fix is embedded in the 1.7.2 release and later. Patching to 1.7.2 or newer removes the vulnerability.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is below 1%, suggesting that current exploitation activity is low, and the vulnerability is not yet listed in the CISA KEV catalog. The available attack vector requires the attacker to supply a crafted command string to the sandbox executor; this can be achieved through any interface that forwards user commands to the system. Successful exploitation would allow arbitrary command execution with the PraisonAI process privileges. Given the high severity and potential impact, administrators should prioritize patching or mitigating the vulnerability.
OpenCVE Enrichment
Github GHSA