CVE-2026-61433

HIGH

PraisonAI before 4.6.78 Code Injection via API deployment generator

Title source: cna
STIX 2.1

Description

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-79fv-7hq9-w7xg)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-79fv-7hq9-w7xg
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 4.6.78 Code Injection via API deployment generator
https://www.vulncheck.com/advisories/praisonai-before-code-injection-via-api-deployment-generator

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 4.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
MervinPraison/PraisonAI < 4.6.78
MervinPraison/PraisonAI 4.6.78
Published Jul 15, 2026
Tracked Since Jul 15, 2026