Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56074

Опубликовано: 18 июн. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.

EPSS

Процентиль: 6%
0.00166
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.5
github
5 месяцев назад

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

EPSS

Процентиль: 6%
0.00166
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-863