CVE-2026-56074 PUBLISHED

PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching

Assigner: VulnCheck
Reserved: 18.06.2026 Published: 18.06.2026 Updated: 18.06.2026

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor PraisonAI
Product PraisonAI
Versions Default: unaffected
  • affected from 0 to 1.5.128 (excl.)
  • Version 1.5.128 is unaffected

Credits

  • offset reporter

References

Problem Types

  • Incorrect Authorization CWE