<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 21:17:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335631</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335631</link>
      <description>EUVD-2026-335631</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335631</guid>
    </item>
    <item>
      <title>fkie_cve-2026-61434</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61434</link>
      <description>&lt;p&gt;PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find&amp;#39;s built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find&amp;#39;s built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-61434</guid>
    </item>
    <item>
      <title>GHSA-cv3g-hj65-pcfh — PraisonAI: Shell command allowlist bypass via find -exec built-in action</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cv3g-hj65-pcfh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The shell command execution hardening introduced in PraisonAI npm 1.7.2 / Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj (utility-tools shell chaining) and GHSA-vjv9-7m7j-h833 (SandboxExecutor chaining) can be bypassed via `find`&amp;#39;s built-in `-exec` action.&lt;/p&gt;
&lt;p&gt;The fix blocks shell metacharacters (`` ;|&amp;amp;`&amp;gt;&amp;lt;$()${} ``) and uses `spawn()` with `shell: false`. However, `find` remains in the safe command allowlist, and its `-exec ... {} +` action executes commands without shell metacharacters — the `+` batch terminator replaces the blocked `;` terminator. The same gap exists in 4 parallel implementations (verified by source inspection of each).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause**: Each of the four implementations validates the **first token** of the command against an allowlist or blocklist, then passes the remaining tokens as arguments to `spawn()`/`subprocess.Popen()` with `shell: false`. Shell metacharacter injection is indeed blocked.&lt;/p&gt;
&lt;p&gt;However, `find` is a Unix command with **built-in execution actions**: `-exec`, `-execdir`, `-delete`, `-ok`, `-okdir`. These actions are interpreted by `find` itself, not by the shell. They execute programs or delete files without shell metacharacters (verified: the payload `find /etc -name passwd -maxdepth 1 -execdir cat {} +` passes the regex at line 240 of utility-tools.ts):&lt;/p&gt;
&lt;p&gt;```
find /path -exec &amp;lt;command&amp;gt; {} +
```&lt;/p&gt;
&lt;p&gt;The `+` terminator (batch mode) avoids `;` which IS blocked by the metacharacter regex.&lt;/p&gt;
&lt;p&gt;**Affected components** (4 implementation…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The shell command execution hardening introduced in PraisonAI npm 1.7.2 / Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj (utility-tools shell chaining) and GHSA-vjv9-7m7j-h833 (SandboxExecutor chaining) can be bypassed via `find`&amp;#39;s built-in `-exec` action.&lt;/p&gt;
&lt;p&gt;The fix blocks shell metacharacters (`` ;|&amp;amp;`&amp;gt;&amp;lt;$()${} ``) and uses `spawn()` with `shell: false`. However, `find` remains in the safe command allowlist, and its `-exec ... {} +` action executes commands without shell metacharacters — the `+` batch terminator replaces the blocked `;` terminator. The same gap exists in 4 parallel implementations (verified by source inspection of each).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Root cause**: Each of the four implementations validates the **first token** of the command against an allowlist or blocklist, then passes the remaining tokens as arguments to `spawn()`/`subprocess.Popen()` with `shell: false`. Shell metacharacter injection is indeed blocked.&lt;/p&gt;
&lt;p&gt;However, `find` is a Unix command with **built-in execution actions**: `-exec`, `-execdir`, `-delete`, `-ok`, `-okdir`. These actions are interpreted by `find` itself, not by the shell. They execute programs or delete files without shell metacharacters (verified: the payload `find /etc -name passwd -maxdepth 1 -execdir cat {} +` passes the regex at line 240 of utility-tools.ts):&lt;/p&gt;
&lt;p&gt;```
find /path -exec &amp;lt;command&amp;gt; {} +
```&lt;/p&gt;
&lt;p&gt;The `+` terminator (batch mode) avoids `;` which IS blocked by the metacharacter regex.&lt;/p&gt;
&lt;p&gt;**Affected components** (4 implementation…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cv3g-hj65-pcfh</guid>
    </item>
  </channel>
</rss>
