PraisonAI versions 4.5.139 and below contain a credential leakage vulnerability in GitHub Actions workflows caused by improper use of actions/checkout without the persist-credentials: false flag. This misconfiguration allows GITHUB_TOKEN and ACTIONS_RUNTIME_TOKEN to be written into .git/config files, which can then be exposed through artifact uploads accessible to any user with read access to the public repository. The vulnerability carries a CVSS 3.1 severity rating of 9.1 (CRITICAL) with a network-based attack vector requiring no privileges or user interaction. Successful exploitation could enable attackers to push malicious code, compromise PyPI and Docker packages, exfiltrate repository secrets, and execute a full supply chain attack affecting all downstream users relying on PraisonAI and its dependencies. There is no current evidence of active exploitation in the wild, and this vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the public nature of the repository and ease of artifact access present a realistic exploitation pathway. The issue has been remediated in version 4.5.140, and organizations should prioritize upgrading immediately to eliminate supply chain risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.140CPE matchmatch criteria | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.