mediumCVSS 5.5Vulnerability
GHSA-x44p-gg67-52fc
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-ffp3-3562-8cv3. This link is maintained to preserve external references. ## Original Description PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.
Properties
- ghsa_id
- GHSA-x44p-gg67-52fc
- severity
- medium
- summary
- Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
- cvss_score
- 5.5
- cve_id
- GHSA-x44p-gg67-52fc
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-06-19T00:31:37Z
- source_url
- https://github.com/advisories/GHSA-x44p-gg67-52fc
- ghsa_updated
- 2026-06-19T21:32:54Z
Related Entities (4)
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]pip/praisonai
AFFECTS (1)
→[Software]pip/praisonai
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
Explore deeper with Ninja Signal's threat intelligence graph