Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vjv9-7m7j-h833 | npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining |
Tue, 15 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mervinpraison
Mervinpraison praisonai |
|
| Vendors & Products |
Mervinpraison
Mervinpraison praisonai |
Tue, 15 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2. | |
| Title | PraisonAI SandboxExecutor allowedCommands bypass via shell chaining | |
| Weaknesses | CWE-693 CWE-78 CWE-863 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T12:40:32.718Z
Reserved: 2026-06-24T00:33:17.708Z
Link: CVE-2026-57136
Updated: 2026-09-15T12:40:22.447Z
Status : Received
Published: 2026-09-15T11:17:10.883
Modified: 2026-09-15T13:16:43.087
Link: CVE-2026-57136
No data.
OpenCVE Enrichment
Updated: 2026-09-15T11:45:17Z
Github GHSA