PT-2026-107589 · Praisonai · Praisonai
CVE-2026-62176
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.6.78
Description
The
deploy/api.py module generates Python server code by directly interpolating the agents file parameter into an f-string, which is subsequently written to a file and executed using subprocess.Popen(). Because the agents file variable is not sanitized or validated, an attacker who controls this value via CLI arguments, configuration, or an upstream API can inject and execute arbitrary Python code on the machine running the deploy command. A similar issue exists in the deploy/docker.py module during Dockerfile generation.Recommendations
Update to version 4.6.78.
Restrict access to the
deploy/api.py and deploy/docker.py modules to minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai