🛡️ CVE-2026-56835 — praisonai

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-862 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

PraisonAI Slack app_mention bypasses configured user/channel authorization

# PraisonAI Slack app_mention bypasses configured user/channel authorization

Summary

PraisonAI's Slack bot applies its configured allowed_users,

allowed_channels, and unknown-user pairing policy in the normal Slack

message event handler, but not in the adjacent Slack app_mention event

handler.

A Slack workspace user who can mention the bot in a channel where the Slack app

is present can trigger the configured PraisonAI agent even when:

  • the sender is not in BotConfig.allowed_users;
  • the channel is not in BotConfig.allowed_channels;
  • unknown_user_policy="deny" is configured; and
  • the same event content is correctly dropped by the normal message handler.

This is a sibling-handler guard-coverage issue. Slack documents

app_mention as a distinct event type rather than a message.* event, so

deployments subscribed to app mentions can route unauthorized sender input

around the guarded message path.

Affected product

  • Repository: MervinPraison/PraisonAI
  • Package: praisonai
  • Component: src/praisonai/praisonai/bots/slack.py
  • Configuration component: src/praisonai-agents/praisonaiagents/bots/config.py

Confirmed affected:

```text

v3.11.0 7f37d754a72511a71f7eeaaa8e9f367a5dc45fd8

v3.11.14 44b800df0eddf32dd5242f47da7513e4a3159d76

v3.12.0 51f95ad904a6616b35caede1cd74026ec8f7152c

v4.4.5 9a3363c900fa3be3fce5483be7f6c1f418757ebb

v4.4.6 90b00f9a25ee5c7ccf4b6ab3152700e1881f262d

v4.4.12 7d0657632fc477673153ad116cecf692b454bfa3

v4.5.2 8ddbb4ee7152d3fa68fbaaf6e6c610ae03d938d3

v4.5.16 02a19776517cc76483fd58dcd6a5fdf8c2c45170

v4.5.28 16f93251766505a79f237a0f07f68a0ecb17e358

v4.5.112 bfe3d94bad6db92fc2927c2e3c081ae8303e209e

v4.5.128 b4e3a8a84ade44ac3dd9102b792cdb4311a95937

v4.6.10 4b1b17b963cbd0625e41394a30168c95b26429b2

v4.6.33 dfbb8d78ec7e8dc7118bc722ab1b2524bc98ddab

v4.6.34 e5928449f73f66cc8af1de61621aa974ab255133

v4.6.56 d3c4a2afadfbf3a3e172e460e607ba4efad263a6

v4.6.57 e90d92231853161ad931f3498da57651a9f8b528

v4.6.58 1ad58ca02975ff1398efeda694ea2ab78f20cf3e

```

Unaffected boundary control:

```text

v3.10.24 de1734c29a50af18cf8c69e1d1d90e0f8e391aae

```

v3.10.24 does not contain src/praisonai/praisonai/bots/slack.py.

Suggested affected range: praisonai >= 3.11.0, <= 4.6.58.

Root cause

The guarded message handler converts the Slack event into a BotMessage,

then applies channel and sender policy before any agent call:

```python

@self._app.event("message")

async def handle_message(event, say):

if event.get("bot_id"):

return

bot_message = self._convert_event_to_message(event)

bot_message._channel_type = "slack"

self.fire_message_received(bot_message)

if not self.config.is_channel_allowed(

bot_message.channel.channel_id if bot_message.channel else ""

):

return

user_id = bot_message.sender.user_id if bot_message.sender else ""

is_explicitly_allowed = (

bool(self.config.allowed_users) and self.config.is_user_allowed(user_id)

)

if not is_explicitly_allowed:

user_allowed = await UnknownUserHandler.handle(bot_message, self._bot_context)

if not user_allowed:

return

```

Only after these checks does handle_message call the session manager and

agent.

The adjacent app_mention handler strips the bot mention and directly invokes

the agent session. It never calls is_channel_allowed(),

is_user_allowed(), or UnknownUserHandler.handle():

```python

@self._app.event("app_mention")

async def handle_mention(event, say):

if event.get("bot_id"):

return

text = event.get("text", "")

if self._bot_user:

text = text.replace(f"<@{self._bot_user.user_id}>", "").strip()

if self._agent:

user_id = event.get("user", "unknown")

response = await self._session.chat(

self._agent, user_id, text,

chat_id=str(event.get("channel", "")),

thread_id=event.get("thread_ts", "") or "",

message_id=event.get("ts", ""),

account=self._config.get("account", "default"),

)

```

Older affected releases use self._agent.chat(text) instead of

self._session.chat(...), but have the same policy gap: message checks

allowed_users and allowed_channels; app_mention does not.

Local-only PoV

Run from the harness checkout:

```fish

env PYTHONPATH="artifacts/repos/praisonai-v4.6.58/src/praisonai:artifacts/repos/praisonai-v4.6.58/src/praisonai-agents" \

python3 submission-bundle/praisonai-prai-cand-017-slack-app-mention-authz-bypass/poc/pov_prai_cand_017_slack_app_mention_authz_bypass.py \

--repo artifacts/repos/praisonai-v4.6.58 \

--label v4.6.58

```

The PoV mocks Slack Bolt and Slack SDK in-process. It does not connect to

Slack, bind a network port, or require real tokens.

The PoV configures:

```python

BotConfig(

allowed_users=["U_ALLOWED"],

allowed_channels=["C_ALLOWED"],

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability low.

Weakness class

CVE-2026-56835 is classified as CWE-862: Missing Authorization. No authorisation check is performed before carrying out a restricted action.

Affected software

CVE-2026-56835 is recorded against 1 package.

  • praisonai (from 3.11.0 up to 4.6.59)

Timeline and source

Published on 18 June 2026 and last revised on 23 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Package)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CWE CWE-862
Public Exploit ✅ No
Source OSV
Published 2026-06-18
Updated 2026-08-12
Modified 2026-07-23
Fix URL N/A

Affected Packages

Software From version Fixed in
praisonai 3.11.0 4.6.59

Similar Threats

Site Security Check

Is praisonai part of your stack?

CVE-2026-56835 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.