Moderate severityNVD Advisory· Published Jun 18, 2026
PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching
CVE-2026-56074
Description
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
praisonaiagentsPyPI | < 4.5.128 | 4.5.128 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/MervinPraison/PraisonAI/security/advisories/GHSA-ffp3-3562-8cv3ghsavendor-advisoryWEB
- github.com/advisories/GHSA-ffp3-3562-8cv3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-56074ghsaADVISORY
- www.vulncheck.com/advisories/praisonai-tool-approval-cache-bypass-via-coarse-grained-cachingghsathird-party-advisoryWEB
- github.com/MervinPraison/PraisonAI/releases/tag/v4.5.128ghsaWEB
News mentions
1- PraisonAI: Five CVEs Disclosed Together — Path Traversal, CORS Misconfig, and Approval BypassesVypr Intelligence · Jun 18, 2026