CVE-2026-61447

CRITICAL

PraisonAI before 1.6.78 Remote Code Execution via CodeAgent

Title source: cna
STIX 2.1

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-2xv2-w8cq-5gxw)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagent

Scores

CVSS v3 10.0
EPSS 0.0074
EPSS Percentile 51.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
MervinPraison/PraisonAI < 1.6.78
MervinPraison/PraisonAI 1.6.78
Published Jul 11, 2026
Tracked Since Jul 11, 2026