<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:06:37.837118+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290882</id>
    <title>EUVD-2026-290882</title>
    <updated>2026-10-03T10:06:37.935508+00:00</updated>
    <content>EUVD-2026-290882</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290882"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40149</id>
    <title>fkie_cve-2026-40149</title>
    <updated>2026-10-03T10:06:37.935553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unauthenticated modification of the tool approval allowlist when no auth_token is configured (the default). By adding dangerous tool names (e.g., shell_exec, file_write) to the allowlist, an attacker can cause the ExecApprovalManager to auto-approve all future agent invocations of those tools, bypassing the human-in-the-loop safety mechanism that the approval system is specifically designed to enforce. This vulnerability is fixed in 4.5.128.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4wr3-f4p3-5wjh</id>
    <title>GHSA-4wr3-f4p3-5wjh — PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls</title>
    <updated>2026-10-03T10:06:37.935608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: PraisonAI</p>
<p>## Summary</p>
<p>The gateway's `/api/approval/allow-list` endpoint permits unauthenticated modification of the tool approval allowlist when no `auth_token` is configured (the default). By adding dangerous tool names (e.g., `shell_exec`, `file_write`) to the allowlist, an attacker can cause the `ExecApprovalManager` to auto-approve all future agent invocations of those tools, bypassing the human-in-the-loop safety mechanism that the approval system is specifically designed to enforce.</p>
<p>## Details</p>
<p>The vulnerability arises from the interaction of three components:</p>
<p>**1. Authentication bypass in default config**</p>
<p>`_check_auth()` in `server.py:243-246` returns `None` (no error) when `self.config.auth_token` is falsy:</p>
<p>```python
# server.py:243-246
def _check_auth(request) -&gt; Optional[JSONResponse]:
    if not self.config.auth_token:
        return None  # No auth configured → allow everything
```</p>
<p>`GatewayConfig` defaults `auth_token` to `None` (`config.py:61`):</p>
<p>```python
# config.py:61
auth_token: Optional[str] = None
```</p>
<p>**2. Unrestricted allowlist modification**</p>
<p>The `approval_allowlist` handler at `server.py:381-420` calls `_check_auth()` and proceeds when it returns `None`:</p>
<p>```python
# server.py:388-410
auth_err = _check_auth(request)
if auth_err:
    return auth_err
# ...
if request.method == "POST":
    _approval_mgr.allowlist.add(tool_name)  # No validation on tool_name
    return JSONResponse({"added": tool_name})
```</p>
<p>There is no validation that `tool_name` corresponds t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4wr3-f4p3-5wjh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2901</id>
    <title>PYSEC-2026-2901 — PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls</title>
    <updated>2026-10-03T10:06:37.935820+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>## Summary</p>
<p>The gateway's `/api/approval/allow-list` endpoint permits unauthenticated modification of the tool approval allowlist when no `auth_token` is configured (the default). By adding dangerous tool names (e.g., `shell_exec`, `file_write`) to the allowlist, an attacker can cause the `ExecApprovalManager` to auto-approve all future agent invocations of those tools, bypassing the human-in-the-loop safety mechanism that the approval system is specifically designed to enforce.</p>
<p>## Details</p>
<p>The vulnerability arises from the interaction of three components:</p>
<p>**1. Authentication bypass in default config**</p>
<p>`_check_auth()` in `server.py:243-246` returns `None` (no error) when `self.config.auth_token` is falsy:</p>
<p>```python
# server.py:243-246
def _check_auth(request) -&gt; Optional[JSONResponse]:
    if not self.config.auth_token:
        return None  # No auth configured → allow everything
```</p>
<p>`GatewayConfig` defaults `auth_token` to `None` (`config.py:61`):</p>
<p>```python
# config.py:61
auth_token: Optional[str] = None
```</p>
<p>**2. Unrestricted allowlist modification**</p>
<p>The `approval_allowlist` handler at `server.py:381-420` calls `_check_auth()` and proceeds when it returns `None`:</p>
<p>```python
# server.py:388-410
auth_err = _check_auth(request)
if auth_err:
    return auth_err
# ...
if request.method == "POST":
    _approval_mgr.allowlist.add(tool_name)  # No validation on tool_name
    return JSONResponse({"added": tool_name})
```</p>
<p>There is no validation that `tool_name` corresponds t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2901"/>
  </entry>
</feed>
