Description
PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped AI SDK executes tool handlers during generation, a callback that returns false records tool_rejected only after the denied tool has already produced side effects and populated toolResults. Applications using onToolCall as a human or policy approval boundary can therefore execute rejected file, command, API, or data-modifying operations. This issue is fixed in version 1.7.2.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Execution of disallowed operations leading to code execution
Action: Patch immediately
AI Analysis

Impact

PraisonAI’s createAgentLoop() invoked on versions 1.4.0 through 1.7.2 incorrectly supplies executable tool definitions to the AI SDK’s generateText function before it calls the onToolCall approval callback. Because the SDK runs tool handlers during text generation, a callback that returns false to reject an operation records tool_rejected only after that tool has already performed its actions. Consequently, an application that treats onToolCall as a human or policy approval gate can inadvertently execute rejected file operations, commands, API calls, or data modifications before the rejection is logged. This flaw permits the execution of disallowed operations, effectively bypassing intended security controls. The problem is resolved in patch version 1.7.2 and later.

Affected Systems

Vendors affected are MervinPraison, product PraisonAI. All releases from version 1.4.0 up to but not including 1.7.2 are vulnerable. The issue was fixed in version 1.7.2 and later releases.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score, being less than 1%, suggests a low but non‑zero probability of exploitation as of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an application or user that relies on onToolCall for human or policy approval; an attacker can craft a prompt or manipulate the tool list to trigger execution of a forbidden tool, have it run before the approval callback denies it, and thereby produce side effects such as file creation, command execution, or data modification. The flaw requires that the application allows the tool to be invoked via the AI SDK, and that it trusts onToolCall the same as a hard enforcement boundary.

Generated by OpenCVE AI on September 17, 2026 at 17:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 1.7.2 or later to apply the fix that enforces approval before tool execution.
  • Configure the system to reject any tool execution until after approval, ensuring that onToolCall is invoked prior to tool invocation.
  • Monitor tool execution logs for unexpected file or command operations and audit any bypass attempts.

Generated by OpenCVE AI on September 17, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h2w2-v7j6-xqm4 npm PraisonAI AgentLoop onToolCall approval runs after tool execution
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped AI SDK executes tool handlers during generation, a callback that returns false records tool_rejected only after the denied tool has already produced side effects and populated toolResults. Applications using onToolCall as a human or policy approval boundary can therefore execute rejected file, command, API, or data-modifying operations. This issue is fixed in version 1.7.2.
Title PraisonAI AgentLoop onToolCall approval runs after tool execution
Weaknesses CWE-693
CWE-862
CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:46:04.174Z

Reserved: 2026-06-24T01:45:48.696Z

Link: CVE-2026-57137

cve-icon Vulnrichment

Updated: 2026-09-15T12:45:10.885Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:11.030

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses