Unrated severityNVD Advisory· Published Jun 18, 2026
PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override
CVE-2026-56075
Description
PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable. Authenticated attackers can instruct the LLM agent to execute arbitrary shell commands via subprocess.run with shell=True, bypassing the manual approval gate and insufficient command sanitization blocklists.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
1- PraisonAI: Five CVEs Disclosed Together — Path Traversal, CORS Misconfig, and Approval BypassesVypr Intelligence · Jun 18, 2026