Critical AICoder Flaw in PraisonAI Lets Prompt Injection Trigger Root-Level File Write and Command Execution
What Happened
A newly published GitHub Security Advisory (GHSA-9mp3-24cc-77mg, tracked as CVE-2026-61445) details two unauthenticated-adjacent vulnerabilities in the AICoder UI component of PraisonAI, a Python package distributed via pip. According to the advisory, the component exposes two tools to its LLM backend — write_to_file and execute_command — with no path validation and no command sanitization.
The reported flaw in write_to_file is a path traversal: the code builds file paths with os.path.join(self.cwd, args["path"]), which does not strip absolute paths, so a supplied path like /etc/cron.d/backdoor is written as-is rather than being confined to the working directory. Separately, execute_command passes an LLM-derived command string directly to asyncio.create_subprocess_exec with no allowlist or sandboxing. The advisory notes both tool calls can be reached through prompt injection in the chat interface, and that PraisonAI's Docker containers run as root with no USER directive, so a successful exploit inherits root privileges inside the container. A public PoC is referenced in the advisory, and the item carries a CVSS score of 9.9.
Why It Matters
This is a case where the attack surface is the LLM's own tool-calling behavior rather than a traditional network-facing endpoint. Any user-supplied text reaching the chat interface — including content embedded in documents, web pages, or other data the LLM ingests — is a potential injection vector that can cause the model to invoke write_to_file or execute_command on the attacker's behalf. Organizations running PraisonAI's AICoder feature, particularly in containerized deployments, should treat this as a path to full host/container compromise: arbitrary file overwrite (e.g., SSH authorized_keys, cron entries) plus arbitrary command execution, combined with root-level container privileges, is a direct route to persistence and lateral movement.
What Defenders Should Watch For
- Inventory whether PraisonAI (and specifically the AICoder UI component) is deployed anywhere in your environment, and check the installed version against the fix referenced in the advisory.
- Treat any LLM-driven coding/agent tool that can write files or execute shell commands as a privileged capability — review whether it runs as root in containers and whether it has an effective allowlist for paths and commands.
- Hunt for anomalous file writes outside expected working directories (e.g., writes to
/etc/cron.d,/root/.ssh/authorized_keys, systemd unit paths) originating from processes associated with PraisonAI or similar LLM-agent tooling. - Monitor subprocess/command execution spawned by AI-agent processes for unexpected network tools (curl, wget, reverse shells) consistent with post-injection payload delivery.
- Until patched, consider restricting or disabling AICoder's file-write and command-execution tools, running the service as a non-root user, and applying strict input handling on any chat interface that feeds this component.
Developing Intel
This is a same-day advisory and details may evolve as vendor remediation and community analysis continue. For the full technical write-up and proof-of-concept details, see the original GitHub Security Advisory: GHSA-9mp3-24cc-77mg.