PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the complete original string to child_process.exec(). A string that starts with an allowed read-only command can append a second non-allowlisted command through shell syntax, allowing arbitrary command execution with the PraisonAI process privileges. This issue is fixed in version 1.7.2.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5jv7-2mjm-h6qj | npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mervinpraison
Mervinpraison praisonai |
|
| Vendors & Products |
Mervinpraison
Mervinpraison praisonai |
Tue, 15 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the complete original string to child_process.exec(). A string that starts with an allowed read-only command can append a second non-allowlisted command through shell syntax, allowing arbitrary command execution with the PraisonAI process privileges. This issue is fixed in version 1.7.2. | |
| Title | PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining | |
| Weaknesses | CWE-693 CWE-78 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T10:24:37.405Z
Reserved: 2026-06-24T00:33:17.708Z
Link: CVE-2026-57133
No data.
Status : Deferred
Published: 2026-09-15T11:17:10.437
Modified: 2026-09-15T14:45:28.563
Link: CVE-2026-57133
No data.
OpenCVE Enrichment
Updated: 2026-09-15T11:30:11Z
Github GHSA