CVE-2026-56075: PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override

Published Jun 18, 2026
·
Updated

PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approvalmode to auto, overriding administrator configuration from PRAISONAPPROVALMODE environment variable. Authenticated attackers can instruct the LLM agent to execute arbitrary shell commands via subprocess.run with shell=True, bypassing the manual approval gate and insufficient command sanitization blocklists.

Affected Software

1 affected component
PraisonAI praisonai<4.5.128

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PraisonAI to a version that resolves this vulnerability.

    Fixed in 4.5.128
  2. Configuration

    Update PraisonAI so the UI modules no longer hardcode approval_mode to auto in versions before 4.5.128; ensure approval_mode follows the administrator configuration specified by the PRAISON_APPROVAL_MODE environment variable.

    PraisonAI UI modules approval_mode = auto (hardcoded in vulnerable versions; override to administrator-configured value via PRAISON_APPROVAL_MODE)

Event History

Jun 18, 2026
CVE Published
via MITRE·10:12 PM
Data Sourced
via MITRE·10:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Jan 30, 58435
Event
via NVD·08:37 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-56075?

The severity of CVE-2026-56075 is high, with a CVSS score of 8.8.

2

What kind of vulnerability is CVE-2026-56075?

CVE-2026-56075 is an arbitrary shell command execution vulnerability found in PraisonAI.

3

How do I fix CVE-2026-56075?

To fix CVE-2026-56075, upgrade to PraisonAI version 4.5.128 or later.

4

Who is affected by CVE-2026-56075?

Authenticated attackers can exploit CVE-2026-56075 if they have access to the PraisonAI application.

5

What does CVE-2026-56075 exploit in PraisonAI?

CVE-2026-56075 exploits a hardcoded approval mode that overrides administrator configuration, enabling arbitrary command execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203