CVE-2026-61443

HIGH

PraisonAI before 1.6.78 Remote Code Execution via SkillTools

Title source: cna
STIX 2.1

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-c44f-37qr-gw3f)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c44f-37qr-gw3f
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 1.6.78 Remote Code Execution via SkillTools
https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-skilltools

Scores

CVSS v3 8.1
EPSS 0.0050
EPSS Percentile 40.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
MervinPraison/PraisonAI < 1.6.78
MervinPraison/PraisonAI 1.6.78
Published Jul 15, 2026
Tracked Since Jul 15, 2026