PT-2026-107589 · Praisonai · Praisonai

CVE-2026-62176

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.78
Description The deploy/api.py module generates Python server code by directly interpolating the agents file parameter into an f-string, which is subsequently written to a file and executed using subprocess.Popen(). Because the agents file variable is not sanitized or validated, an attacker who controls this value via CLI arguments, configuration, or an upstream API can inject and execute arbitrary Python code on the machine running the deploy command. A similar issue exists in the deploy/docker.py module during Dockerfile generation.
Recommendations Update to version 4.6.78. Restrict access to the deploy/api.py and deploy/docker.py modules to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62176
GHSA-G6J7-PFFP-8WHG

Affected Products

Praisonai