info: name: praisonai cve: CVE-2026-56840 summary: PraisonAI HTTPApproval Dashboard XSS allows auto-approval of dangerous tool calls via injected JavaScript details: 'PraisonAI''s HTTPApproval backend (praisonai.bots.HTTPApproval) renders pending tool approval arguments directly into the approval dashboard HTML without escaping. In src/praisonai/praisonai/bots/_http_approval.py, _build_html() builds the approval page using raw f-string interpolation: argument keys and values are appended to args_html without HTML escaping, and tool_name, risk_level, and agent_name are also interpolated into the returned HTML. The generated page contains same-origin JavaScript that posts to /approve/{request_id}/decide. _handle_decide() accepts JSON from that endpoint and marks the pending request approved when decision == "approve". An attacker-controlled tool argument can inject JavaScript into the approval page. When a human opens the approval URL to inspect the risky tool request, the injected script runs in the dashboard origin and can POST to the same request''s /approve/{request_id}/decide endpoint, causing HTTPApproval to return approved=True. The request_id is unguessable, but the script runs inside the loaded approval page and can derive the endpoint from location.pathname. This allows attacker-controlled tool arguments to execute script in the approval page and submit the approval action, bypassing the human-in-the-loop safety control. This is distinct from the previously published stored-XSS advisory for agent output rendering (src/praisonai/api.py). This vulnerability concerns the HTTPApproval dashboard sink and remains present in current head. Versions 4.5.0 and 4.5.1 do not contain the HTTPApproval backend and are not affected. The vulnerability is classified as HIGH with CVSS v3.1 score 8.1 and vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The affected CWE is CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-site Scripting). The fix in PraisonAI version 4.6.59 adds HTML escaping to _build_html() and moves the approval decision token outside attacker-controlled rendered argument fields.' cvss: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity: HIGH security_advise: Upgrade PraisonAI to version 4.6.59 or later via 'pip install --upgrade praisonai>=4.6.59'. Additionally, avoid using HTTPApproval for dangerous tools until patched, restrict network access to the approval dashboard endpoint, and consider using console-based or channel-based approval backends that are not susceptible to XSS. rule: version >= "4.5.2" && version < "4.6.59" references: - https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-63v4-w882-g4x2