CVE-2026-60087
MEDIUM6.1CVSS v3
—CVSS v2
0.19%
EPSS (exploit probability)
CWE-863CWE
Description
PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arbitrary arguments. Attackers can exploit this by obtaining approval for a benign operation and then executing dangerous file write operations with unreviewed parameters in the same session.
CVSS v3 vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Affected routers (0)
No routers currently mapped to this CVE in our database.