CVE-2026-60085

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-15 12:18

Updated : 2026-07-15 19:50


NVD link : CVE-2026-60085

Mitre link : CVE-2026-60085

CVE.ORG link : CVE-2026-60085


JSON object : View

Products Affected

No product.

CWE
CWE-273

Improper Check for Dropped Privileges