info: name: praisonai cve: CVE-2026-56832 summary: PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals details: 'PraisonAI''s DiscordApproval (praisonai.bots.DiscordApproval) approves a pending dangerous tool call when it sees any later non-bot message in the configured Discord channel whose text is classified as approval, such as "yes". The decision is not bound to a Discord reply to the approval message, a Discord thread created for that request, a Discord interaction/button callback for that request, an explicit approver user allowlist, or an approval nonce visible only to intended approvers. As a result, any user who can post in the configured approval channel can approve a pending high-risk tool call by sending "yes" after the approval message appears. The primary affected file is src/praisonai/praisonai/bots/_discord_approval.py. The Slack and Telegram messaging approval backends also lack an explicit approver identity parameter, but the primary issue is the Discord backend''s unthreaded channel cross-talk: the approving message does not need to be a reply or otherwise request-bound. If an application uses DiscordApproval for dangerous tools such as shell commands, file writes, deletes, deployments, or other privileged operations, a low-privileged Discord user with write access to the configured approval channel can approve pending dangerous tool executions. This can lead to code execution, file modification, deployment changes, or data access with the privileges of the PraisonAI process. The vulnerability is classified as HIGH with CVSS v3.1 score 8.8 and vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The affected CWEs are CWE-345 (Insufficient Verification of Data Authenticity) and CWE-863 (Incorrect Authorization). The fix in PraisonAI version 4.6.59 adds request-bound approval binding and explicit approver identity checks to all messaging approval backends.' cvss: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity: HIGH security_advise: Upgrade PraisonAI to version 4.6.59 or later via 'pip install --upgrade praisonai>=4.6.59'. Additionally, restrict approval channel membership to only trusted approvers and review DiscordApproval configuration to ensure request-bound approvals are enforced. rule: version < "4.6.59" references: - https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8579-rgg5-ph2m