Vulnerability  ·  2026-06-20

PraisonAI Shell Command Execution — Approval Mode Override via Hardcoded auto Configuration

VulnerabilityHigh impactGlobalCVE-2026-56075
PraisonAI's UI modules hardcode approval_mode=auto, bypassing administrator configuration from PRAISON_APPROVAL_MODE environment variable. This allows authenticated attackers to instruct the agent to execute arbitrary shell commands without approval prompts.
Agentic AI systems with shell execution capability can modify code, exfiltrate data, or compromise the host system. Approval mode is a critical safeguard. Hardcoding auto approval removes human-in-the-loop controls and enables lateral movement.
UI modules in PraisonAI hardcode approval_mode to 'auto', overriding the PRAISON_APPROVAL_MODE environment variable set by administrators. An authenticated attacker can instruct the LLM agent to execute arbitrary shell commands, which are automatically approved without human review.
PraisonAI < 4.5.128
Upgrade to PraisonAI 4.5.128 or later. Enforce approval_mode via environment variable and remove hardcoded auto approvals.
Sources
CVE-2026-56075 NVD DetailPraisonAI GitHub Security Advisory GHSA-qwgj-rrpj-75xmVulnCheck Advisory - CVE-2026-56075
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →