Unrated severityNVD Advisory· Published Jun 18, 2026
PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching
CVE-2026-56074
Description
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentials via subsequent shell commands without user consent.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.5.128
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/MervinPraison/PraisonAI/security/advisories/GHSA-ffp3-3562-8cv3mitrevendor-advisory
- www.vulncheck.com/advisories/praisonai-tool-approval-cache-bypass-via-coarse-grained-cachingmitrethird-party-advisory
News mentions
0No linked articles in our index yet.