CVE-2026-56074 Details
Description
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.
A vulnerability in PraisonAI versions prior to 1.5.128 allows for a bypass of tool approval prompts. The issue arises because the application caches approval decisions based solely on tool names, without considering the specific arguments used in each invocation. This flaw enables attackers to first gain approval for a harmless command and then exploit the system to covertly exfiltrate API keys and credentials through later shell commands, all without the user's knowledge or consent.
Users can update to PraisonAI version 1.5.128 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-ffp3-3562-8cv3 | CISA-ADP | AdvisoryExploitTechnical AnalysisVendor |
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-ffp3-3562-8cv3 | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/praisonai-tool-approval-cache-bypass-via-coarse-grained-caching | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PraisonAI | <= 4.5.124 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion