CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56838

highCVSS 7.8covered by 1 sourcefirst seen 2026-06-18
PraisonAI recipe.run_stream() skips dangerous-tool policy enforcement Summary PraisonAI recipe execution blocks default-denied dangerous tools unless the caller explicitly passes allow_dangerous_tools=True. The normal recipe.run() path enforces this with _check_tool_policy(). The streaming path, recipe.run_stream(), loads the same recipe, checks dependencies, and then calls _execute_recipe() without running the dangerous-tool policy check. As a result, a recipe that honestly declares execute_command in TEMPLATE.yaml requires.tools is denied by recipe.run(), but reaches the execution engine through recipe.run_stream() with allow_dangerous_tools=False. The local PoV uses a harmless printf canary, explicitly unsets PRAISONAI_AUTO_APPROVE, and avoids network access. Affected Product - Repository: MervinPraison/PraisonAI - Package: praisonai - Components: - src/praisonai/praisonai/recipe/core.py - src/praisonai/praisonai/recipe/serve.py - src/praisonai/praisonai/cli/features/recipe.py - src/praisonai-agents/praisonaiagents/workflows/yaml_parser.py - src/praisonai-agents/praisonaiagents/workflows/workflows.py Validated affected: - current main 2f9677abb2ea68eab864ee8b6a828fd0141612e1 (v4.6.57-4-g2f9677ab) - v4.6.57 - v4.6.56 - v4.6.10 - v4.6.9 - v4.5.128 - v4.5.120 - v4.5.96 - v4.5.87 Suggested affected range: >= 4.5.87, <= 4.6.57. PyPI lists PraisonAI 4.6.57 as the latest release on 2026-06-13. Earlier tested tags through v4.5.85 failed in this source checkout before the tested workflow path due an unrelated praisonaiagents.output.models import error. They are not claimed fixed or unaffected. Root Cause recipe.run() enforces the dangerous-tool gate: if not options.get("allow_dangerous_tools", False): policy_error = _check_tool_policy(recipe_config) if policy_error: return RecipeResult(..., status=RecipeStatus.POLICY_DENIED, ...) recipe.run_stream() has a sibling execution path. It loads the recipe and checks dependencies, but then goes directly to executio

⚡ Watch CVE-2026-56838

Get an email if CVE-2026-56838 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-56838

CVE.org record

Embed the live status

CVE-2026-56838 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56838 status](https://www.csirts.com/badge/CVE-2026-56838)](https://www.csirts.com/cve/CVE-2026-56838)