Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox
Vulnerability Description
PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
MervinPraison PraisonAI 命令注入漏洞
Vulnerability Description
MervinPraison PraisonAI是MervinPraison个人开发者的 MervinPraison PraisonAI 4.6.78之前版本存在命令注入漏洞,该漏洞源于JobWorkflowExecutor._exec_inline_python()函数对工作流脚本步骤的AST验证不足,可能导致攻击者创建恶意YAML工作流文件,通过import os语句及os.system()调用绕过沙箱检查,以进程权限执行任意OS命令。
CVSS Information
N/A
Vulnerability Type
N/A