Tools AI Risk Radar ai-incident-0080
Incident record
PraisonAI's jobs API took any caller's YAML and let it pre-approve its own commands
- Severity
- Critical
- Status
- Patched
- Type
- Agent Hijack
- Target
- praisonai through 4.6.48 and praisonaiagents through 1.6.48
- Actor
- researcher
- CVE
- CVE-2026-57125
What happened
The unauthenticated POST /api/v1/runs endpoint accepts attacker-controlled agent_yaml, and an approve field in that YAML marks execute_command as pre-approved, turning the require_approval decorator into a no-op. The chain gives full remote command execution with no credentials and no operator interaction, scored CVSS 3.1 9.8. Patched in praisonai 4.6.59 and praisonaiagents 1.6.59.
One of at least eight PraisonAI CVE records published on 14 September. The verified companions include an IMAP command injection through LLM-controlled email fields scored 8.1 and an authentication bypass through the PRAISONAI_CALL_AUTH environment variable scored 8.2, fixed in 4.6.62.
Sources
- PraisonAI advisory GHSA-4869-x4pr-q22xgithub.com/MervinPraison/PraisonAI/security/advisories/GHSA-…
- PraisonAI release v4.6.59github.com/MervinPraison/PraisonAI/releases/tag/v4.6.59
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026