PraisonAI recipe execution has a dangerous-tool policy that is supposed to block default-denied tools unless the caller explicitly passes allow_dangerous_tools=True. That policy only checks tools declared in TEMPLATE.yaml requires.tools.
For steps-based recipes, the actual execution path loads workflow.yaml with YAMLWorkflowParser. That parser resolves agent-level tools: declarations and preserves top-level approve:. Workflow.start() then installs those YAML-approved tools into the approval context.
As a result, an untrusted recipe can omit execute_command from TEMPLATE.yaml requires.tools, declare it in workflow.yaml agents.*.tools, and add top-level approve: [execute_command]. The caller did not set allow_dangerous_tools=True, but the recipe policy allows the recipe and the workflow approval path self-approves the critical shell tool.
The local PoV uses a harmless printf canary and explicitly unsets PRAISONAI_AUTO_APPROVE.
recipe.run() checks the recipe policy unless options["allow_dangerous_tools"] is true. _check_tool_policy() gets the required tool list from recipe_config.get_required_tools(), which is backed by TEMPLATE.yaml requires.tools.
The steps workflow execution path is separate:
_execute_steps_workflow() parses the workflow file with YAMLWorkflowParser.YAMLWorkflowParser resolves agents.*.tools.approve: and stores it on workflow.approve_tools.Workflow.start() calls set_yaml_approved_tools(approve_tools).execute_command is listed as a default dangerous tool with critical risk and is decorated with @require_approval(risk_level="critical"). The policy gap is that recipe-level dangerous-tool enforcement does not inspect the workflow file that actually supplies and approves the tool.
YAML approve: is an intended feature. This report is not claiming that workflow-level approval is inherently unintended.
The unintended behavior is that the recipe dangerous-tool policy exposes an operator-facing explicit override, allow_dangerous_tools=True, but a recipe can avoid that policy by moving the dangerous tool declaration from TEMPLATE.yaml requires.tools into the steps workflow. The recipe still runs through the standard recipe runner path, and the same workflow can self-approve the critical tool.
This conflicts with the documented safety model:
A control recipe that declares requires.tools: [execute_command] is denied with:
Tool 'execute_command' is denied by default. Use allow_dangerous_tools=True to override.
The bypass recipe uses the same tool but omits it from requires.tools; it passes policy and reaches the recipe runner's dry-run state.
Run:
python3 poc/poc.py
Expected output:
{
"ok": true,
"control_policy": "Tool 'execute_command' is denied by default. Use allow_dangerous_tools=True to override.",
"control_recipe_status": "policy_denied",
"bypass_policy": null,
"bypass_recipe_dry_run_status": "dry_run",
"workflow_approve_tools": [
"execute_command"
],
"runner_tool_names": [
"execute_command"
],
"command_stdout": "poc",
"operator_env_auto_approve": null
}
The PoV creates two temporary recipes:
TEMPLATE.yaml requires.tools: [execute_command]. recipe.run() returns policy_denied.TEMPLATE.yaml, but with workflow.yaml declaring execute_command under an agent and approve: [execute_command]. recipe.run(..., dry_run=True) reaches dry_run, and the same parser/approval context permits a harmless `printf poc.The PoV section above contains the local reproduction command, input, and decisive output.
If an operator runs an untrusted recipe, or exposes the recipe runner to users who can choose recipe names/URIs, the recipe can self-authorize a default-denied critical shell tool without the operator setting allow_dangerous_tools=True.
Successful exploitation lets the workflow run execute_command with the privileges of the PraisonAI process if the agent reaches the tool call. The exact trigger depends on the workflow and model/tool-call path, but the policy boundary is already bypassed before execution.
This can affect both local CLI use and HTTP recipe-runner deployments. The HTTP recipe runner defaults to localhost/no-auth and requires auth for non-localhost binding, so this report uses local/UI-required severity rather than claiming an unauthenticated network RCE by default.
The local HTTP sidecar documentation also frames the sidecar as a localhost REST API for local/polyglot integration. If a deployment exposes that API to authenticated users who can choose recipe names or URIs, the same policy bypass can become an authenticated remote recipe-execution issue, but that is not the default severity claim.
Suggested severity: High.
Normalize and validate the actual workflow tool graph before recipe execution:
_check_tool_policy().workflow.yaml agents.*.tools, roles.*.tools, included recipes, and other workflow-resolved tool lists in the dangerous-tool policy.approve: as an operator-supplied approval policy, not a recipe-controlled bypass of the recipe-level dangerous-tool gate.approve: remains recipe-controlled, ignore dangerous/default-denied tool entries unless the caller passed allow_dangerous_tools=True or an explicit external policy allowed that exact tool.TEMPLATE.yaml requires.tools is denied;workflow.yaml agents.*.tools is also denied;approve: [execute_command] does not bypass the recipe policy;allow_dangerous_tools=True keeps the intended opt-in behavior.MervinPraison/PraisonAIpraisonaisrc/praisonai/praisonai/recipe/core.pysrc/praisonai/praisonai/recipe/models.pysrc/praisonai-agents/praisonaiagents/workflows/yaml_parser.pysrc/praisonai-agents/praisonaiagents/workflows/workflows.pysrc/praisonai-agents/praisonaiagents/approval/registry.pyValidated affected:
2f9677abb2ea68eab864ee8b6a828fd0141612e1v4.6.57v4.6.56v4.6.10v4.6.9v4.5.128v4.5.120v4.5.96v4.5.87Suggested affected range: >= 4.5.87, <= 4.6.57.
PyPI lists PraisonAI 4.6.57 as the latest release on 2026-06-13.
Earlier tested tags through v4.5.85 failed in this source checkout before the tested workflow path due an unrelated praisonaiagents.output.models import error. They are not claimed fixed or unaffected.
Checked visible PraisonAI advisories and prior submissions for the same root cause, affected entrypoint, and exploit preconditions. No exact duplicate is identified in this report text. Adjacent advisories, where relevant, are listed in References or discussed above.
| Software | From | Fixed in |
|---|---|---|
praisonai
|
4.5.87 | 4.6.61 |
A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.
CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.
A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.
Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.
Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.
SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.