YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0080

Incident record

PraisonAI's jobs API took any caller's YAML and let it pre-approve its own commands

Severity
Critical
Status
Patched
Type
Agent Hijack
Target
praisonai through 4.6.48 and praisonaiagents through 1.6.48
Actor
researcher
CVE
CVE-2026-57125

What happened

The unauthenticated POST /api/v1/runs endpoint accepts attacker-controlled agent_yaml, and an approve field in that YAML marks execute_command as pre-approved, turning the require_approval decorator into a no-op. The chain gives full remote command execution with no credentials and no operator interaction, scored CVSS 3.1 9.8. Patched in praisonai 4.6.59 and praisonaiagents 1.6.59.

One of at least eight PraisonAI CVE records published on 14 September. The verified companions include an IMAP command injection through LLM-controlled email fields scored 8.1 and an authentication bypass through the PRAISONAI_CALL_AUTH environment variable scored 8.2, fixed in 4.6.62.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026