


Perceptive Security
SOC/SIEM Consultancy

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it e…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 20:02:16
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Identity & Access
PraisonAI, a multi-agent teams system, contains a critical command injection vulnerability in its bundled Claude GitHub Actions workflow in versions prior to 4.6.40. The flaw arises because attacker-controlled pull request branch names are embedded into Bash run blocks without quoting or validation. Any external contributor can open a pull request from a fork with a maliciously crafted branch name containing shell metacharacters and trigger the vulnerability by commenting @claude, as the workflow imposes no collaborator trust checks. Exploitation allows arbitrary shell code execution within the GitHub Actions runner environment. The runner holds a GitHub App token with write permissions, OIDC access, and gh/git access, enabling privilege escalation through $GITHUB_PATH manipulation. Potential impacts include unauthorized repository writes, pull request and issue manipulation, and OIDC token abuse. The vulnerability has been patched in version 4.6.40.
Technical details
Mitigation steps:
Affected products:
PraisonAI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48168
https://github.com/MervinPraison/PraisonAI/commit/179cab02dbec0c1e9b601507a659
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xp85-6wwf-r67c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
