CVE-2026-61438

HIGH

PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox

Title source: cna
STIX 2.1

Description

PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-26mh-57q7-jfvr)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-26mh-57q7-jfvr
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox
https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-broken-ast-sandbox

Scores

CVSS v3 7.3
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
MervinPraison/PraisonAI < 4.6.78
MervinPraison/PraisonAI 4.6.78
Published Jul 15, 2026
Tracked Since Jul 15, 2026