Impact
PraisonAI before version 4.6.78 contains missing path validation and command sanitization in its AICoder component, allowing attackers to inject malicious prompts through the chat interface to write files to any filesystem location and execute arbitrary shell commands with root privileges.
Affected Systems
The vulnerable versions are all releases of MervinPraison PraisonAI prior to 4.6.78.
Risk and Exploitability
The CVSS score of 9.4 reflects critical severity. EPSS score of < 1% indicates a very low but nonzero exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Attackers with access to the public or privileged chat interface can remotely exploit the flaw, as inferred from the description.
OpenCVE Enrichment