Skip to main content
EPSS 0.9%top 42%

CVE-2026-48168: CWE-862: Missing Authorization in MervinPraison PraisonAI

0
Critical
VulnerabilityCVE-2026-48168cvecve-2026-48168cwe-862
Published: 08/05/2026 (08/05/2026, 18:29:38 UTC)
Source: CVE Database V5
Vendor/Project: MervinPraison
Product: PraisonAI

Description

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborator. An outside contributor can open a pull request from a fork whose branch name contains shell metacharacters and comment @claude, causing Bash to execute arbitrary shell code in the GitHub Actions runner. Because these commands run in a job holding a GitHub App token with write permissions, OIDC access, and gh/git access, the injection can be chained through $GITHUB_PATH to compromise later privileged steps, enabling repository writes, pull request and issue manipulation, or OIDC-token abuse. This issue has been fixed in version 4.6.40.

CVSS v3.1

Score 10.0critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected software

MervinPraison

PraisonAI

Affected versions
<4.6.40
GitHub Actionsmore threats →ai
mervinpraison/PraisonAI
pkg:github/mervinpraison/PraisonAI
Affected versions
<4.6.40

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 19:26:37 UTC

Technical Analysis

CVE-2026-48168 affects MervinPraison's PraisonAI multi-agent teams system in versions before 4.6.40. The vulnerability arises from the bundled Claude GitHub Actions workflow embedding an unquoted, attacker-controlled pull request branch name into a Bash run block, enabling command injection. Additionally, the workflow triggers on any @claude comment without verifying if the commenter is a trusted collaborator. An attacker can open a pull request from a fork with a malicious branch name containing shell metacharacters and comment @claude to execute arbitrary shell commands in the GitHub Actions runner. Since the job runs with a GitHub App token that has write permissions, OIDC access, and git access, the attacker can chain this injection to compromise subsequent privileged steps, potentially modifying repository contents, manipulating pull requests and issues, or abusing OIDC tokens. The vulnerability is resolved in PraisonAI version 4.6.40.

Potential Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary shell commands within the GitHub Actions runner environment. This can lead to full repository compromise including write access, manipulation of pull requests and issues, and abuse of OIDC tokens for further privilege escalation. The vulnerability has a CVSS 3.1 score of 10.0 (critical), indicating maximum impact on confidentiality, integrity, and availability.

Mitigation Recommendations

Upgrade PraisonAI to version 4.6.40 or later, where this vulnerability has been fixed. Until then, restrict GitHub Actions workflows to trusted collaborators and avoid triggering jobs based on unverified comments. Review and validate any inputs embedded in shell commands within workflows to prevent command injection.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-20T23:12:43.032Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a738b03bf8831d53956b2a7

Added to database: 08/05/2026, 19:12:03 UTC

Last enriched: 08/05/2026, 19:26:37 UTC

Last updated: 09/18/2026, 00:56:11 UTC

Views: 115

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses