Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Lhmisme420

#32078of 56,337
8.7Total CVSS
Vulnerabilities · 1
PT-2026-60133
8.7
2026-07-15
Praisonai · Praisonai · CVE-2026-60085
**Name of the Vulnerable Software and Affected Versions** PraisonAI versions prior to 4.6.78 **Description** The default Subprocess Sandbox backend fails to enforce security policies. Specifically, restrictions defined in `blocked commands`, `blocked paths`, `blocked imports`, `allow subprocess`, and `allow file write` are ignored. This allows attackers to execute arbitrary subprocess commands, read sensitive files, and perform destructive operations regardless of the security policy configuration. **Recommendations** Update PraisonAI to version 4.6.78 or later.