<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:06:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-328847</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328847</link>
      <description>EUVD-2026-328847</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328847</guid>
    </item>
    <item>
      <title>fkie_cve-2026-56074</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56074</link>
      <description>&lt;p&gt;PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-56074</guid>
    </item>
    <item>
      <title>GHSA-ffp3-3562-8cv3 — PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ffp3-3562-8cv3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The approval system in PraisonAI Agents caches tool approval decisions by tool name only, not by invocation arguments. Once a user approves `execute_command` for any command (e.g., `ls -la`), all subsequent `execute_command` calls in that execution context bypass the approval prompt entirely. Combined with `os.environ.copy()` passing all process environment variables to subprocesses, this allows an LLM agent (potentially via prompt injection) to silently exfiltrate API keys and credentials without further user consent.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `require_approval` decorator in `src/praisonai-agents/praisonaiagents/approval/__init__.py:176-178` checks approval status by tool name only:&lt;/p&gt;
&lt;p&gt;```python
@wraps(func)
def wrapper(*args, **kwargs):
    if is_already_approved(tool_name):   # line 177 — checks only tool_name
        return func(*args, **kwargs)     # line 178 — bypasses ALL approval
```&lt;/p&gt;
&lt;p&gt;The `mark_approved` function in `registry.py:144-147` stores only the tool name string:&lt;/p&gt;
&lt;p&gt;```python
def mark_approved(self, tool_name: str) -&amp;gt; None:
    approved = self._approved_context.get(set())
    approved.add(tool_name)              # stores &amp;#34;execute_command&amp;#34;, not args
    self._approved_context.set(approved)
```&lt;/p&gt;
&lt;p&gt;The approval context is never cleared during agent execution — `clear_approved()` exists (`registry.py:152`) but is never called in the agent&amp;#39;s tool execution path (`agent/tool_execution.py`).&lt;/p&gt;
&lt;p&gt;Meanwhile, the `ConsoleBackend` UI at `backends.py:95-96` misleads the user:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The approval system in PraisonAI Agents caches tool approval decisions by tool name only, not by invocation arguments. Once a user approves `execute_command` for any command (e.g., `ls -la`), all subsequent `execute_command` calls in that execution context bypass the approval prompt entirely. Combined with `os.environ.copy()` passing all process environment variables to subprocesses, this allows an LLM agent (potentially via prompt injection) to silently exfiltrate API keys and credentials without further user consent.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `require_approval` decorator in `src/praisonai-agents/praisonaiagents/approval/__init__.py:176-178` checks approval status by tool name only:&lt;/p&gt;
&lt;p&gt;```python
@wraps(func)
def wrapper(*args, **kwargs):
    if is_already_approved(tool_name):   # line 177 — checks only tool_name
        return func(*args, **kwargs)     # line 178 — bypasses ALL approval
```&lt;/p&gt;
&lt;p&gt;The `mark_approved` function in `registry.py:144-147` stores only the tool name string:&lt;/p&gt;
&lt;p&gt;```python
def mark_approved(self, tool_name: str) -&amp;gt; None:
    approved = self._approved_context.get(set())
    approved.add(tool_name)              # stores &amp;#34;execute_command&amp;#34;, not args
    self._approved_context.set(approved)
```&lt;/p&gt;
&lt;p&gt;The approval context is never cleared during agent execution — `clear_approved()` exists (`registry.py:152`) but is never called in the agent&amp;#39;s tool execution path (`agent/tool_execution.py`).&lt;/p&gt;
&lt;p&gt;Meanwhile, the `ConsoleBackend` UI at `backends.py:95-96` misleads the user:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ffp3-3562-8cv3</guid>
    </item>
    <item>
      <title>PYSEC-2026-2946 — PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2946</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The approval system in PraisonAI Agents caches tool approval decisions by tool name only, not by invocation arguments. Once a user approves `execute_command` for any command (e.g., `ls -la`), all subsequent `execute_command` calls in that execution context bypass the approval prompt entirely. Combined with `os.environ.copy()` passing all process environment variables to subprocesses, this allows an LLM agent (potentially via prompt injection) to silently exfiltrate API keys and credentials without further user consent.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `require_approval` decorator in `src/praisonai-agents/praisonaiagents/approval/__init__.py:176-178` checks approval status by tool name only:&lt;/p&gt;
&lt;p&gt;```python
@wraps(func)
def wrapper(*args, **kwargs):
    if is_already_approved(tool_name):   # line 177 — checks only tool_name
        return func(*args, **kwargs)     # line 178 — bypasses ALL approval
```&lt;/p&gt;
&lt;p&gt;The `mark_approved` function in `registry.py:144-147` stores only the tool name string:&lt;/p&gt;
&lt;p&gt;```python
def mark_approved(self, tool_name: str) -&amp;gt; None:
    approved = self._approved_context.get(set())
    approved.add(tool_name)              # stores &amp;#34;execute_command&amp;#34;, not args
    self._approved_context.set(approved)
```&lt;/p&gt;
&lt;p&gt;The approval context is never cleared during agent execution — `clear_approved()` exists (`registry.py:152`) but is never called in the agent&amp;#39;s tool execution path (`agent/tool_execution.py`).&lt;/p&gt;
&lt;p&gt;Meanwhile, the `ConsoleBackend` UI at `backends.py:95-96` misleads the user:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The approval system in PraisonAI Agents caches tool approval decisions by tool name only, not by invocation arguments. Once a user approves `execute_command` for any command (e.g., `ls -la`), all subsequent `execute_command` calls in that execution context bypass the approval prompt entirely. Combined with `os.environ.copy()` passing all process environment variables to subprocesses, this allows an LLM agent (potentially via prompt injection) to silently exfiltrate API keys and credentials without further user consent.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The `require_approval` decorator in `src/praisonai-agents/praisonaiagents/approval/__init__.py:176-178` checks approval status by tool name only:&lt;/p&gt;
&lt;p&gt;```python
@wraps(func)
def wrapper(*args, **kwargs):
    if is_already_approved(tool_name):   # line 177 — checks only tool_name
        return func(*args, **kwargs)     # line 178 — bypasses ALL approval
```&lt;/p&gt;
&lt;p&gt;The `mark_approved` function in `registry.py:144-147` stores only the tool name string:&lt;/p&gt;
&lt;p&gt;```python
def mark_approved(self, tool_name: str) -&amp;gt; None:
    approved = self._approved_context.get(set())
    approved.add(tool_name)              # stores &amp;#34;execute_command&amp;#34;, not args
    self._approved_context.set(approved)
```&lt;/p&gt;
&lt;p&gt;The approval context is never cleared during agent execution — `clear_approved()` exists (`registry.py:152`) but is never called in the agent&amp;#39;s tool execution path (`agent/tool_execution.py`).&lt;/p&gt;
&lt;p&gt;Meanwhile, the `ConsoleBackend` UI at `backends.py:95-96` misleads the user:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2946</guid>
    </item>
  </channel>
</rss>
