<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:57:24.540702+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-40153</id>
    <title>CVE-2026-40153 — PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in…</title>
    <updated>2026-10-03T12:57:24.542453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> MervinPraison PraisonAIAgents</p>
<p>PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using shell=False (line 88) for security. This allows exfiltration of secrets stored in environment variables (database credentials, API keys, cloud access keys). The approval system displays the unexpanded $VAR references to human reviewers, creating a deceptive approval where the displayed command differs from what actually executes. This vulnerability is fixed in 1.5.128.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-40153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v8g7-9q6v-p3x8</id>
    <title>GHSA-v8g7-9q6v-p3x8 — PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool</title>
    <updated>2026-10-03T12:57:24.542509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonaiagents</p>
<p>## Summary</p>
<p>The `execute_command` function in `shell_tools.py` calls `os.path.expandvars()` on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using `shell=False` (line 88) for security. This allows exfiltration of secrets stored in environment variables (database credentials, API keys, cloud access keys). The approval system displays the **unexpanded** `$VAR` references to human reviewers, creating a deceptive approval where the displayed command differs from what actually executes.</p>
<p>## Details</p>
<p>The vulnerable code is in `src/praisonai-agents/praisonaiagents/tools/shell_tools.py`:</p>
<p>```python
# Line 60: command is split
command = shlex.split(command)</p>
<p># Lines 62-64: VULNERABLE — expands ALL env vars in every argument
# Expand tilde and environment variables in command arguments
# (shell=False means the shell won't do this for us)
command = [os.path.expanduser(os.path.expandvars(arg)) for arg in command]</p>
<p># Line 88: shell=False is supposed to prevent shell feature access
process = subprocess.Popen(
    command,
    ...
    shell=False,  # Always use shell=False for security
)
```</p>
<p>The security problem is a disconnect between the approval display and actual execution:</p>
<p>1. The LLM generates a tool call: `execute_command(command="cat $DATABASE_URL")`
2. `_check_tool_approval_sync` in `tool_execution.py:558` passes `{"command": "cat $DATABASE_URL"}` to the approval backend
3. `ConsoleBackend` (backends.py:81-85) displ…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v8g7-9q6v-p3x8"/>
  </entry>
</feed>
