<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T07:21:17.819045+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335631</id>
    <title>EUVD-2026-335631</title>
    <updated>2026-10-10T07:21:17.879647+00:00</updated>
    <content>EUVD-2026-335631</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61434</id>
    <title>fkie_cve-2026-61434</title>
    <updated>2026-10-10T07:21:17.879685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61434"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cv3g-hj65-pcfh</id>
    <title>GHSA-cv3g-hj65-pcfh — PraisonAI: Shell command allowlist bypass via find -exec built-in action</title>
    <updated>2026-10-10T07:21:17.879727+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>### Summary</p>
<p>The shell command execution hardening introduced in PraisonAI npm 1.7.2 / Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj (utility-tools shell chaining) and GHSA-vjv9-7m7j-h833 (SandboxExecutor chaining) can be bypassed via `find`'s built-in `-exec` action.</p>
<p>The fix blocks shell metacharacters (`` ;|&amp;`&gt;&lt;$()${} ``) and uses `spawn()` with `shell: false`. However, `find` remains in the safe command allowlist, and its `-exec ... {} +` action executes commands without shell metacharacters — the `+` batch terminator replaces the blocked `;` terminator. The same gap exists in 4 parallel implementations (verified by source inspection of each).</p>
<p>### Details</p>
<p>**Root cause**: Each of the four implementations validates the **first token** of the command against an allowlist or blocklist, then passes the remaining tokens as arguments to `spawn()`/`subprocess.Popen()` with `shell: false`. Shell metacharacter injection is indeed blocked.</p>
<p>However, `find` is a Unix command with **built-in execution actions**: `-exec`, `-execdir`, `-delete`, `-ok`, `-okdir`. These actions are interpreted by `find` itself, not by the shell. They execute programs or delete files without shell metacharacters (verified: the payload `find /etc -name passwd -maxdepth 1 -execdir cat {} +` passes the regex at line 240 of utility-tools.ts):</p>
<p>```
find /path -exec &lt;command&gt; {} +
```</p>
<p>The `+` terminator (batch mode) avoids `;` which IS blocked by the metacharacter regex.</p>
<p>**Affected components** (4 implementation…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cv3g-hj65-pcfh"/>
  </entry>
</feed>
