PT-2026-108670 · Pypi · Praisonai

Published

2026-07-15

·

Updated

2026-07-15

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-79fv-7hq9-w7xg. This link is maintained to preserve external references.

Original Description

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents file configuration parameters that execute when the generated server starts or handles requests.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-QPQ9-HWX9-CWGC

Affected Products

Praisonai