Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-48168: PraisonAI: Unsecured GitHub Actions Workflow Exposes GitHub Data

CVE-2026-48168 · published 1 month ago
Summary

PraisonAI's GitHub Actions workflow is vulnerable to attacks if an unauthorized contributor submits a pull request with malicious branch name and comments '@claude'. This could allow them to manipulate sensitive data or execute unauthorized actions on the repository. Update to PraisonAI version 4.6.40 or later to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
mervinpraison praisonai < 4.6.40
Original advisory text
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull req...
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborator. An outside contributor can open a pull request from a fork whose branch name contains shell metacharacters and comment @claude, causing Bash to execute arbitrary shell code in the GitHub Actions runner. Because these commands run in a job holding a GitHub App token with write permissions, OIDC access, and gh/git access, the injection can be chained through $GITHUB_PATH to compromise later privileged steps, enabling repository writes, pull request and issue manipulation, or OIDC-token abuse. This issue has been fixed in version 4.6.40.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published5 Aug 2026
Updated3 Sep 2026
First seen5 Aug 2026
Sources
CVE-2026-48168 · MITRE
Monitor software like this
Free during beta