PT-2026-108670 · Pypi · Praisonai
Publicado
2026-07-15
·
Atualizado
2026-07-15
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-79fv-7hq9-w7xg. This link is maintained to preserve external references.
Original Description
PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents file configuration parameters that execute when the generated server starts or handles requests.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Praisonai