CVE-2026-48168Patch

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborator. An outside contributor can open a pull request from a fork whose branch name contains shell metacharacters and comment @claude, causing Bash to execute arbitrary shell code in the GitHub Actions runner. Because these commands run in a job holding a GitHub App token with write permissions, OIDC access, and gh/git access, the injection can be chained through $GITHUB_PATH to compromise later privileged steps, enabling repository writes, pull request and issue manipulation, or OIDC-token abuse. This issue has been fixed in version 4.6.40.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Exploit: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-06); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-06: 1Mentions · 2026-08-11: 1Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-11: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-14: 108-0608-1108-14
Signal classification3 categories
Patch
133.3%
Exploit
133.3%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-061
Patch1
2026-08-111
Exploit1
2026-08-141
Disclosure1
Full discourse3 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🎯 GitHub Actions and CI/CD Pipelines Under Siege Two perfect-10 CVEs this week target the software delivery pipeline itself — one of the most dangerous places an attacker can land. CVE-2026-48168 (CVSS 10.0) affects PraisonAI's…

    Post summary

    The tweet announces two newly disclosed perfect‑10 CVEs targeting the software delivery pipeline, with CVE‑2026‑48168 affecting PraionAI and graded CVSS 10.0. No PoC, exploit, or patch information is provided.

    1000035
    88 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - PraisonAI GitHub Actions PR Branch Name Command Injection (CVE-2026-48168) PraisonAI’s bundled Claude GitHub Actions workflow injects the attacker-controlled PR branch name into a bash run: block without quoting, enabling command injection. Any user can trigger it via an @claude comment, executing arbitrary shell on the runner and abusing the GitHub App token (OIDC + git/gh) for repo/PR manipulation or token theft. 👉Affected: PraisonAI < 4.6.40 | Upgrade to 4.6.40

    Post summary

    The announcement details a critical command‑injection flaw in PraisonAI’s GitHub Actions workflow, advises that the issue is fixed in version 4.6.40, and suggests upgrading to mitigate the risk.

    00010165
    282 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Exploit

    ⚠️ CVE of the week — CVE-2026-48168 (CVSS 10.0) · NVD/NIST 💣 Exploit available https://sec.kaitan.id/cves/CVE-2026-48168?utm_source=x&utm_campaign=tuesday_highlight 📬 Weekly recap → https://sec.kaitan.id/blog #cybersecurity #cve #vulnmanagement #kaitanid https://t.co/qIDgdGGWjj

    Post summary

    The message announces CVE‑2026‑48168, highlights that an exploit exists, and provides a link for details, but lacks explicit code or technical specifics.

    0000051
    88 followersView on X

Explore more