Description
PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-29r9-67vg-qj56)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-29r9-67vg-qj56
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 1.6.78 Tool Approval Cache Bypass
https://www.vulncheck.com/advisories/praisonai-before-tool-approval-cache-bypass
Scores
CVSS v3
6.1
EPSS
0.0019
EPSS Percentile
8.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
MervinPraison/PraisonAI
< 1.6.78
MervinPraison/PraisonAI
1.6.78
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026