Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65c8-r727-2mpj

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.

EPSS

Процентиль: 16%
0.00241
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-273

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.

EPSS

Процентиль: 16%
0.00241
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-273