Disclosure summary
### Summary The `AICoder` UI component exposes `write_to_file` and `execute_command` tools to the LLM with no path validation and no command sanitization. An attacker can achieve arbitrary file write to any location on the filesystem (including `/root/.ssh/authorized_keys`, `/etc/crontab`) and arbitrary command execution through prompt injection in the chat interface. Docker containers run as root, maximizing impact. ### Details #### Path Traversal in write_to_file `src/praisonai/praisonai/ui/components/aicoder.py` (lines 122-131): ```python async def write_to_file(self, file_path, content, existing=False): if not existing: await self.create_directories(file_path) try: with open(file_path, 'w') as file: # No path validation file.write(content) return True except Exception as e: return False ``` The `apply_llm_response` method at line 269 uses `os.path.join` which does not prevent absolute paths: ```python file_path = os.path.join(self.cwd, args["path"].strip()) # os.path.join("/app", "/etc/passwd") = "/etc/passwd" ``` #### Command Injection in execute_command `src/praisonai/praisonai/ui/components/aicoder.py` (lines 159-180): ```python async def execute_command(self, command: str):
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-9mp3-24cc-77mg
Open original source · Updated Oct 08, 2026
PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | praisonai | 4.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-08T18:00:40-04:00
MODIFIED 2026-10-08T18:00:41-04:00
INGESTED 2026-10-10T20:25:14-04:00