<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:37:34.392851+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368474</id>
    <title>EUVD-2026-368474</title>
    <updated>2026-10-05T18:37:34.442668+00:00</updated>
    <content>EUVD-2026-368474</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57136</id>
    <title>fkie_cve-2026-57136</title>
    <updated>2026-10-05T18:37:34.442713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57136"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vjv9-7m7j-h833</id>
    <title>GHSA-vjv9-7m7j-h833 — npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining</title>
    <updated>2026-10-05T18:37:34.442776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: praisonai</p>
<p>## Summary</p>
<p>The published npm package `praisonai` exports `SandboxExecutor`, `CommandValidator`, and `sandboxExec` as "safe command execution with restrictions." When `allowedCommands` is configured, `CommandValidator` checks only the first whitespace-delimited token of the command string. `SandboxExecutor` then passes the entire original string to `spawn("sh", ["-c", command])`.</p>
<p>With a policy that allows only `echo`, this direct command is correctly rejected:</p>
<p>```sh
cat /tmp/marker
```</p>
<p>but this chained command is accepted and executed:</p>
<p>```sh
echo allowed; cat /tmp/marker
```</p>
<p>The shell executes `cat` even though `cat` is not allowlisted. This bypasses the command allowlist and can execute arbitrary shell commands with the PraisonAI process privileges when an application, CLI workflow, or agent pipeline exposes sandbox command execution to lower-trust users, prompts, or model output.</p>
<p>The PoV is deterministic and local-only. It creates and reads only a temporary marker file.</p>
<p>## Technical Details</p>
<p>In `src/praisonai-ts/src/cli/features/sandbox-executor.ts`, `CommandValidator.validate()` normalizes the command and authorizes only the first whitespace token:</p>
<p>```ts
const normalized = command.toLowerCase().trim();</p>
<p>if (this.allowedCommands) {
  const baseCmd = normalized.split(/\s+/)[0];
  if (!this.allowedCommands.includes(baseCmd)) {
    return { valid: false, reason: `Command '${baseCmd}' not in allowlist` };
  }
}
```</p>
<p>The denylist does not generally reject shell separato…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vjv9-7m7j-h833"/>
  </entry>
</feed>
