CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-57125

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-06-18
Unauthenticated Remote Code Execution via Jobs API and Approval Bypass in PraisonAI Summary An unauthenticated attacker can execute arbitrary OS commands on any server running the PraisonAI Jobs API by submitting a crafted workflow YAML. The attack chains two weaknesses: the /api/v1/runs endpoint requires no credentials, and a top-level approve field in the submitted YAML unconditionally bypasses the @require_approval safety decorator on dangerous tools such as execute_command. Ecosystem: pip | Package: praisonai | Affected: <= 4.6.48 | Patched: *(none)* Details Step 1 — No authentication on the Jobs API POST /api/v1/runs accepts and executes agent jobs from any caller with no token or session required: src/praisonai/praisonai/jobs/router.py:47 @router.post("", response_model=JobSubmitResponse, status_code=202) async def submit_job( request: Request, body: JobSubmitRequest, # accepts agent_yaml from anyone ... missing: _: None = Depends(verify_token) ): Compare with the authenticated endpoint in api/agent_invoke.py, which correctly includes Depends(verify_token). Step 2 — approve YAML field bypasses @require_approval The YAML parser extracts an attacker-controlled approve list and loads it into a ContextVar that the approval decorator consults before every tool call: src/praisonai-agents/praisonaiagents/workflows/yaml_parser.py:261 approve_tools = data.get('approve', []) # attacker-controlled workflow.approve_tools = approve_tools # line 370 src/praisonai-agents/praisonaiagents/workflows/workflows.py:1025 if approve_tools: _approval_token = set_yaml_approved_tools(approve_tools) adds "execute_command" to ContextVar — bypasses decorator src/praisonai-agents/praisonaiagents/approval/init.py:179 if is_yaml_approved(tool_name): # → True mark_approved(tool_name) return func(*args, **kwargs) # executes without prompting Because the bypass is evaluated before any risk-level check, supplying approve: [execute_command] in the submitted YAML is sufficient to

⚡ Watch CVE-2026-57125

Get an email if CVE-2026-57125 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-57125

CVE.org record

Embed the live status

CVE-2026-57125 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-57125 status](https://www.csirts.com/badge/CVE-2026-57125)](https://www.csirts.com/cve/CVE-2026-57125)