CVE-2026-61447
CRITICALPraisonAI before 1.6.78 Remote Code Execution via CodeAgent
Title source: cnaDescription
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-2xv2-w8cq-5gxw)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagent
Scores
CVSS v3
10.0
EPSS
0.0074
EPSS Percentile
51.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (2)
MervinPraison/PraisonAI
< 1.6.78
MervinPraison/PraisonAI
1.6.78
Published
Jul 11, 2026
Tracked Since
Jul 11, 2026