CVE-2026-40154: Praisonai Tool Static Destructive File Op Without Workspace Guard
A `@staticmethod` on a file-tooling class performs a destructive filesystem operation (os.remove / os.unlink / shutil.move / shutil.rmtree / shutil.copy / shutil.copy2) without invoking a workspace authorization guard such as `self._require_workspace_access(write=True)` first. When such a method is exposed as an agent tool (e.g., PraisonAI FileTools loaded b
greprules fetch cve-2026-40154-praisonai-tool-static-destructive-file-op-without-workspace-guard --engine opengrepDescription
A `@staticmethod` on a file-tooling class performs a destructive filesystem operation (os.remove / os.unlink / shutil.move / shutil.rmtree / shutil.copy / shutil.copy2) without invoking a workspace authorization guard such as `self._require_workspace_access(write=True)` first. When such a method is exposed as an agent tool (e.g., PraisonAI FileTools loaded b
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.