CVE-2026-61434: PraisonAI before 4.6.78 Allowlist Bypass via find -exec
PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PraisonAIto a version that resolves this vulnerability.Fixed in 4.6.78 - Compensating control
If you cannot upgrade immediately, block or restrict the use of find's built-in actions -exec, -execdir, and -delete in the environment where PraisonAI executes shell commands, to prevent allowlist bypass through those find actions.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61434?
The severity of CVE-2026-61434 is rated high with a score of 8.7.
How do I fix CVE-2026-61434?
To fix CVE-2026-61434, upgrade your PraisonAI to version 4.6.78 or later.
What type of vulnerability is CVE-2026-61434?
CVE-2026-61434 is classified as an OS Command Injection vulnerability.
What impact does CVE-2026-61434 have?
CVE-2026-61434 allows attackers to bypass the allowlist and execute restricted commands, leading to unauthorized access to sensitive files.
Which versions of PraisonAI are affected by CVE-2026-61434?
PraisonAI versions prior to 4.6.78 are affected by CVE-2026-61434.