top of page
perceptive_background_267k.jpg

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it e…

Published:

4 augustus 2026 om 22:00:00

Alert date:

5 augustus 2026 om 20:02:16

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies, Identity & Access

PraisonAI, a multi-agent teams system, contains a critical command injection vulnerability in its bundled Claude GitHub Actions workflow in versions prior to 4.6.40. The flaw arises because attacker-controlled pull request branch names are embedded into Bash run blocks without quoting or validation. Any external contributor can open a pull request from a fork with a maliciously crafted branch name containing shell metacharacters and trigger the vulnerability by commenting @claude, as the workflow imposes no collaborator trust checks. Exploitation allows arbitrary shell code execution within the GitHub Actions runner environment. The runner holds a GitHub App token with write permissions, OIDC access, and gh/git access, enabling privilege escalation through $GITHUB_PATH manipulation. Potential impacts include unauthorized repository writes, pull request and issue manipulation, and OIDC token abuse. The vulnerability has been patched in version 4.6.40.

Technical details

Mitigation steps:

Affected products:

PraisonAI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page