Back

MEDIUM

PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching

Published Jun 18, 2026

Description

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 18, 2026
Updated Jun 22, 2026
Reserved Jun 18, 2026
CISA Vulnrichment
Updated Jun 22, 2026
NVD
Status Deferred
Modified Jun 22, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-FFP3-3562-8CV3