<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T18:06:59.530073+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336479</id>
    <title>EUVD-2026-336479</title>
    <updated>2026-10-10T18:06:59.534470+00:00</updated>
    <content>EUVD-2026-336479</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61445</id>
    <title>fkie_cve-2026-61445</title>
    <updated>2026-10-10T18:06:59.534504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61445"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9mp3-24cc-77mg</id>
    <title>GHSA-9mp3-24cc-77mg — PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls</title>
    <updated>2026-10-10T18:06:59.534536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>### Summary
The `AICoder` UI component exposes `write_to_file` and `execute_command` tools to the LLM with no path validation and no command sanitization. An attacker can achieve arbitrary file write to any location on the filesystem (including `/root/.ssh/authorized_keys`, `/etc/crontab`) and arbitrary command execution through prompt injection in the chat interface. Docker containers run as root, maximizing impact.</p>
<p>### Details</p>
<p>#### Path Traversal in write_to_file</p>
<p>`src/praisonai/praisonai/ui/components/aicoder.py` (lines 122-131):</p>
<p>```python
async def write_to_file(self, file_path, content, existing=False):
    if not existing:
        await self.create_directories(file_path)
    try:
        with open(file_path, 'w') as file:  # No path validation
            file.write(content)
        return True
    except Exception as e:
        return False
```</p>
<p>The `apply_llm_response` method at line 269 uses `os.path.join` which does not prevent absolute paths:
```python
file_path = os.path.join(self.cwd, args["path"].strip())
# os.path.join("/app", "/etc/passwd") = "/etc/passwd"
```</p>
<p>#### Command Injection in execute_command</p>
<p>`src/praisonai/praisonai/ui/components/aicoder.py` (lines 159-180):</p>
<p>```python
async def execute_command(self, command: str):
    cmd_args = self.get_shell_command(command)
    process = await asyncio.create_subprocess_exec(
        *cmd_args,
        stdout=asyncio.subprocess.PIPE,
        stderr=asyncio.subprocess.PIPE,
        cwd=self.cwd
    )
```</p>
<p>No…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9mp3-24cc-77mg"/>
  </entry>
</feed>
