Praisonai · Praisonai · CVE-2026-60085
**Name of the Vulnerable Software and Affected Versions**
PraisonAI versions prior to 4.6.78
**Description**
The default Subprocess Sandbox backend fails to enforce security policies. Specifically, restrictions defined in `blocked commands`, `blocked paths`, `blocked imports`, `allow subprocess`, and `allow file write` are ignored. This allows attackers to execute arbitrary subprocess commands, read sensitive files, and perform destructive operations regardless of the security policy configuration.
**Recommendations**
Update PraisonAI to version 4.6.78 or later.