VulnWatch VulnWatch
← Back to dashboard
Medium github · GHSA-cfxv-8fw8-rwpv

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

Published Aug 25, 2026 CVSS 6.1

Target: PraisonAI (MervinPraison/PraisonAI) Affected component: praisonaiagents/tools/ast_grep_tool.pyast_grep_rewrite Affected versions: master at ce97667156a116c50b4a3d1aa21e09f048903fda; reproduced against the current praisonaiagents PyPI release (praisonaiagents

Affected AI Products

llm agent llm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.