CVE-2026-61445

CRITICAL

PraisonAI before 4.6.78 Arbitrary File Write and Command Execution

Title source: cna
STIX 2.1

Description

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-9mp3-24cc-77mg)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9mp3-24cc-77mg
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
https://www.vulncheck.com/advisories/praisonai-before-arbitrary-file-write-and-command-execution

Scores

CVSS v3 9.9
EPSS 0.0054
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
MervinPraison/PraisonAI < 4.6.78
MervinPraison/PraisonAI 4.6.78
Published Jul 11, 2026
Tracked Since Jul 11, 2026