CVE-2026-48168: CWE-862: Missing Authorization in MervinPraison PraisonAI
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborator. An outside contributor can open a pull request from a fork whose branch name contains shell metacharacters and comment @claude, causing Bash to execute arbitrary shell code in the GitHub Actions runner. Because these commands run in a job holding a GitHub App token with write permissions, OIDC access, and gh/git access, the injection can be chained through $GITHUB_PATH to compromise later privileged steps, enabling repository writes, pull request and issue manipulation, or OIDC-token abuse. This issue has been fixed in version 4.6.40.
AI Analysis
Technical Summary
CVE-2026-48168 affects MervinPraison's PraisonAI multi-agent teams system in versions before 4.6.40. The vulnerability arises from the bundled Claude GitHub Actions workflow embedding an unquoted, attacker-controlled pull request branch name into a Bash run block, enabling command injection. Additionally, the workflow triggers on any @claude comment without verifying if the commenter is a trusted collaborator. An attacker can open a pull request from a fork with a malicious branch name containing shell metacharacters and comment @claude to execute arbitrary shell commands in the GitHub Actions runner. Since the job runs with a GitHub App token that has write permissions, OIDC access, and git access, the attacker can chain this injection to compromise subsequent privileged steps, potentially modifying repository contents, manipulating pull requests and issues, or abusing OIDC tokens. The vulnerability is resolved in PraisonAI version 4.6.40.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary shell commands within the GitHub Actions runner environment. This can lead to full repository compromise including write access, manipulation of pull requests and issues, and abuse of OIDC tokens for further privilege escalation. The vulnerability has a CVSS 3.1 score of 10.0 (critical), indicating maximum impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade PraisonAI to version 4.6.40 or later, where this vulnerability has been fixed. Until then, restrict GitHub Actions workflows to trusted collaborators and avoid triggering jobs based on unverified comments. Review and validate any inputs embedded in shell commands within workflows to prevent command injection.
CVE-2026-48168: CWE-862: Missing Authorization in MervinPraison PraisonAI
Description
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborator. An outside contributor can open a pull request from a fork whose branch name contains shell metacharacters and comment @claude, causing Bash to execute arbitrary shell code in the GitHub Actions runner. Because these commands run in a job holding a GitHub App token with write permissions, OIDC access, and gh/git access, the injection can be chained through $GITHUB_PATH to compromise later privileged steps, enabling repository writes, pull request and issue manipulation, or OIDC-token abuse. This issue has been fixed in version 4.6.40.
CVSS v3.1
Score 10.0critical
Affected software
MervinPraison
PraisonAI
pkg:github/mervinpraison/PraisonAIRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-48168 affects MervinPraison's PraisonAI multi-agent teams system in versions before 4.6.40. The vulnerability arises from the bundled Claude GitHub Actions workflow embedding an unquoted, attacker-controlled pull request branch name into a Bash run block, enabling command injection. Additionally, the workflow triggers on any @claude comment without verifying if the commenter is a trusted collaborator. An attacker can open a pull request from a fork with a malicious branch name containing shell metacharacters and comment @claude to execute arbitrary shell commands in the GitHub Actions runner. Since the job runs with a GitHub App token that has write permissions, OIDC access, and git access, the attacker can chain this injection to compromise subsequent privileged steps, potentially modifying repository contents, manipulating pull requests and issues, or abusing OIDC tokens. The vulnerability is resolved in PraisonAI version 4.6.40.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary shell commands within the GitHub Actions runner environment. This can lead to full repository compromise including write access, manipulation of pull requests and issues, and abuse of OIDC tokens for further privilege escalation. The vulnerability has a CVSS 3.1 score of 10.0 (critical), indicating maximum impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade PraisonAI to version 4.6.40 or later, where this vulnerability has been fixed. Until then, restrict GitHub Actions workflows to trusted collaborators and avoid triggering jobs based on unverified comments. Review and validate any inputs embedded in shell commands within workflows to prevent command injection.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T23:12:43.032Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a738b03bf8831d53956b2a7
Added to database: 08/05/2026, 19:12:03 UTC
Last enriched: 08/05/2026, 19:26:37 UTC
Last updated: 09/18/2026, 00:56:11 UTC
Views: 115
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.