Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2026-56074— PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching

CVSS 5.5 · Medium
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-56074

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching
Source: NVD (National Vulnerability Database)
Vulnerability Description
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不正确
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
PraisonAIPraisonAI 0 ~ 1.5.128 -

II. Public POCs for CVE-2026-56074

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56074

登录查看更多情报信息。

Vendor Advisories for CVE-2026-56074 (2)

Same Patch Batch · PraisonAI · 2026-06-18 · 5 CVEs total

CVE-2026-560788.8 HIGHPraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor
CVE-2026-560758.8 HIGHPraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override
CVE-2026-560768.1 HIGHPraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentic
CVE-2026-560776.5 MEDIUMPraisonAI - Information Disclosure via Shared MultiAgentLedger State

IV. Related Vulnerabilities

V. Comments for CVE-2026-56074

No comments yet


Leave a comment