<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 17:10:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-336479</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336479</link>
      <description>EUVD-2026-336479</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336479</guid>
    </item>
    <item>
      <title>fkie_cve-2026-61445</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61445</link>
      <description>&lt;p&gt;PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-61445</guid>
    </item>
    <item>
      <title>GHSA-9mp3-24cc-77mg — PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9mp3-24cc-77mg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary
The `AICoder` UI component exposes `write_to_file` and `execute_command` tools to the LLM with no path validation and no command sanitization. An attacker can achieve arbitrary file write to any location on the filesystem (including `/root/.ssh/authorized_keys`, `/etc/crontab`) and arbitrary command execution through prompt injection in the chat interface. Docker containers run as root, maximizing impact.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#### Path Traversal in write_to_file&lt;/p&gt;
&lt;p&gt;`src/praisonai/praisonai/ui/components/aicoder.py` (lines 122-131):&lt;/p&gt;
&lt;p&gt;```python
async def write_to_file(self, file_path, content, existing=False):
    if not existing:
        await self.create_directories(file_path)
    try:
        with open(file_path, &amp;#39;w&amp;#39;) as file:  # No path validation
            file.write(content)
        return True
    except Exception as e:
        return False
```&lt;/p&gt;
&lt;p&gt;The `apply_llm_response` method at line 269 uses `os.path.join` which does not prevent absolute paths:
```python
file_path = os.path.join(self.cwd, args[&amp;#34;path&amp;#34;].strip())
# os.path.join(&amp;#34;/app&amp;#34;, &amp;#34;/etc/passwd&amp;#34;) = &amp;#34;/etc/passwd&amp;#34;
```&lt;/p&gt;
&lt;p&gt;#### Command Injection in execute_command&lt;/p&gt;
&lt;p&gt;`src/praisonai/praisonai/ui/components/aicoder.py` (lines 159-180):&lt;/p&gt;
&lt;p&gt;```python
async def execute_command(self, command: str):
    cmd_args = self.get_shell_command(command)
    process = await asyncio.create_subprocess_exec(
        *cmd_args,
        stdout=asyncio.subprocess.PIPE,
        stderr=asyncio.subprocess.PIPE,
        cwd=self.cwd
    )
```&lt;/p&gt;
&lt;p&gt;No…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;### Summary
The `AICoder` UI component exposes `write_to_file` and `execute_command` tools to the LLM with no path validation and no command sanitization. An attacker can achieve arbitrary file write to any location on the filesystem (including `/root/.ssh/authorized_keys`, `/etc/crontab`) and arbitrary command execution through prompt injection in the chat interface. Docker containers run as root, maximizing impact.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#### Path Traversal in write_to_file&lt;/p&gt;
&lt;p&gt;`src/praisonai/praisonai/ui/components/aicoder.py` (lines 122-131):&lt;/p&gt;
&lt;p&gt;```python
async def write_to_file(self, file_path, content, existing=False):
    if not existing:
        await self.create_directories(file_path)
    try:
        with open(file_path, &amp;#39;w&amp;#39;) as file:  # No path validation
            file.write(content)
        return True
    except Exception as e:
        return False
```&lt;/p&gt;
&lt;p&gt;The `apply_llm_response` method at line 269 uses `os.path.join` which does not prevent absolute paths:
```python
file_path = os.path.join(self.cwd, args[&amp;#34;path&amp;#34;].strip())
# os.path.join(&amp;#34;/app&amp;#34;, &amp;#34;/etc/passwd&amp;#34;) = &amp;#34;/etc/passwd&amp;#34;
```&lt;/p&gt;
&lt;p&gt;#### Command Injection in execute_command&lt;/p&gt;
&lt;p&gt;`src/praisonai/praisonai/ui/components/aicoder.py` (lines 159-180):&lt;/p&gt;
&lt;p&gt;```python
async def execute_command(self, command: str):
    cmd_args = self.get_shell_command(command)
    process = await asyncio.create_subprocess_exec(
        *cmd_args,
        stdout=asyncio.subprocess.PIPE,
        stderr=asyncio.subprocess.PIPE,
        cwd=self.cwd
    )
```&lt;/p&gt;
&lt;p&gt;No…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9mp3-24cc-77mg</guid>
    </item>
  </channel>
</rss>
