THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hxmv-c4g6-5fqc (high) — PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

[GHSA] GHSA-hxmv-c4g6-5fqc (high) — PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

highgithub_advisoriesPublished 2026-08-25

GHSA-hxmv-c4g6-5fqc Severity: high CVE: CVE-2026-55522

PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

## Summary

PraisonAI's workflow include implementation implicitly imports and executes an included recipe's `tools.py` file even when the documented `tools.py` autoload opt-in is unset.

This bypasses the hardening added for the prior automatic `t

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hxmv-c4g6-5fqc