Impact
PraisonAI’s createAgentLoop() invoked on versions 1.4.0 through 1.7.2 incorrectly supplies executable tool definitions to the AI SDK’s generateText function before it calls the onToolCall approval callback. Because the SDK runs tool handlers during text generation, a callback that returns false to reject an operation records tool_rejected only after that tool has already performed its actions. Consequently, an application that treats onToolCall as a human or policy approval gate can inadvertently execute rejected file operations, commands, API calls, or data modifications before the rejection is logged. This flaw permits the execution of disallowed operations, effectively bypassing intended security controls. The problem is resolved in patch version 1.7.2 and later.
Affected Systems
Vendors affected are MervinPraison, product PraisonAI. All releases from version 1.4.0 up to but not including 1.7.2 are vulnerable. The issue was fixed in version 1.7.2 and later releases.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score, being less than 1%, suggests a low but non‑zero probability of exploitation as of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an application or user that relies on onToolCall for human or policy approval; an attacker can craft a prompt or manipulate the tool list to trigger execution of a forbidden tool, have it run before the approval callback denies it, and thereby produce side effects such as file creation, command execution, or data modification. The flaw requires that the application allows the tool to be invoked via the AI SDK, and that it trusts onToolCall the same as a hard enforcement boundary.
OpenCVE Enrichment
Github GHSA