THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cfxv-8fw8-rwpv (medium) — praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

[GHSA] GHSA-cfxv-8fw8-rwpv (medium) — praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

highgithub_advisoriesPublished 2026-08-25

GHSA-cfxv-8fw8-rwpv Severity: medium CVE: CVE-2026-55530

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

**Target:** PraisonAI (`MervinPraison/PraisonAI`) **Affected component:** `praisonaiagents/tools/ast_grep_tool.py` — `ast_grep_rewrite` **Affected versions:** master at `ce97667156a116c50b4a3d1aa21e09f048903

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cfxv-8fw8-rwpv