<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 14:37:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368474</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368474</link>
      <description>EUVD-2026-368474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368474</guid>
    </item>
    <item>
      <title>fkie_cve-2026-57136</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57136</link>
      <description>&lt;p&gt;PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters, causing arbitrary commands to run with the PraisonAI process privileges. This issue is fixed in version 1.7.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-57136</guid>
    </item>
    <item>
      <title>GHSA-vjv9-7m7j-h833 — npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vjv9-7m7j-h833</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: praisonai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The published npm package `praisonai` exports `SandboxExecutor`, `CommandValidator`, and `sandboxExec` as &amp;#34;safe command execution with restrictions.&amp;#34; When `allowedCommands` is configured, `CommandValidator` checks only the first whitespace-delimited token of the command string. `SandboxExecutor` then passes the entire original string to `spawn(&amp;#34;sh&amp;#34;, [&amp;#34;-c&amp;#34;, command])`.&lt;/p&gt;
&lt;p&gt;With a policy that allows only `echo`, this direct command is correctly rejected:&lt;/p&gt;
&lt;p&gt;```sh
cat /tmp/marker
```&lt;/p&gt;
&lt;p&gt;but this chained command is accepted and executed:&lt;/p&gt;
&lt;p&gt;```sh
echo allowed; cat /tmp/marker
```&lt;/p&gt;
&lt;p&gt;The shell executes `cat` even though `cat` is not allowlisted. This bypasses the command allowlist and can execute arbitrary shell commands with the PraisonAI process privileges when an application, CLI workflow, or agent pipeline exposes sandbox command execution to lower-trust users, prompts, or model output.&lt;/p&gt;
&lt;p&gt;The PoV is deterministic and local-only. It creates and reads only a temporary marker file.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;In `src/praisonai-ts/src/cli/features/sandbox-executor.ts`, `CommandValidator.validate()` normalizes the command and authorizes only the first whitespace token:&lt;/p&gt;
&lt;p&gt;```ts
const normalized = command.toLowerCase().trim();&lt;/p&gt;
&lt;p&gt;if (this.allowedCommands) {
  const baseCmd = normalized.split(/\s+/)[0];
  if (!this.allowedCommands.includes(baseCmd)) {
    return { valid: false, reason: `Command &amp;#39;${baseCmd}&amp;#39; not in allowlist` };
  }
}
```&lt;/p&gt;
&lt;p&gt;The denylist does not generally reject shell separato…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: praisonai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The published npm package `praisonai` exports `SandboxExecutor`, `CommandValidator`, and `sandboxExec` as &amp;#34;safe command execution with restrictions.&amp;#34; When `allowedCommands` is configured, `CommandValidator` checks only the first whitespace-delimited token of the command string. `SandboxExecutor` then passes the entire original string to `spawn(&amp;#34;sh&amp;#34;, [&amp;#34;-c&amp;#34;, command])`.&lt;/p&gt;
&lt;p&gt;With a policy that allows only `echo`, this direct command is correctly rejected:&lt;/p&gt;
&lt;p&gt;```sh
cat /tmp/marker
```&lt;/p&gt;
&lt;p&gt;but this chained command is accepted and executed:&lt;/p&gt;
&lt;p&gt;```sh
echo allowed; cat /tmp/marker
```&lt;/p&gt;
&lt;p&gt;The shell executes `cat` even though `cat` is not allowlisted. This bypasses the command allowlist and can execute arbitrary shell commands with the PraisonAI process privileges when an application, CLI workflow, or agent pipeline exposes sandbox command execution to lower-trust users, prompts, or model output.&lt;/p&gt;
&lt;p&gt;The PoV is deterministic and local-only. It creates and reads only a temporary marker file.&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;In `src/praisonai-ts/src/cli/features/sandbox-executor.ts`, `CommandValidator.validate()` normalizes the command and authorizes only the first whitespace token:&lt;/p&gt;
&lt;p&gt;```ts
const normalized = command.toLowerCase().trim();&lt;/p&gt;
&lt;p&gt;if (this.allowedCommands) {
  const baseCmd = normalized.split(/\s+/)[0];
  if (!this.allowedCommands.includes(baseCmd)) {
    return { valid: false, reason: `Command &amp;#39;${baseCmd}&amp;#39; not in allowlist` };
  }
}
```&lt;/p&gt;
&lt;p&gt;The denylist does not generally reject shell separato…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vjv9-7m7j-h833</guid>
    </item>
  </channel>
</rss>
