Vulnerability Description
PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or execute non-allowlisted binaries without triggering shell metacharacter filters.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cv3g-hj65-pc
- https://www.vulncheck.com/advisories/praisonai-before-allowlist-bypass-via-find-
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cv3g-hj65-pc
FAQ
What is CVE-2026-61434?
CVE-2026-61434 is a vulnerability with a CVSS score of 8.8 (HIGH). PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -del...
How severe is CVE-2026-61434?
CVE-2026-61434 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-61434?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.