PT-2026-57194 · Pypi · Praisonaiagents

·

CVE-2026-61437

·

Published

2026-07-10

·

Updated

2026-07-12

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions praisonaiagents versions prior to 1.6.78
Description An unsafe dynamic module loading issue exists in the AgentFlow. resolve pydantic class() function. When a workflow step utilizes a string output pydantic reference, the framework imports a sibling tools.py file from the workflow directory using importlib exec module without sandboxing. This process ignores the PRAISONAI ALLOW * TOOLS environment variables. An attacker who can control a workflow file and its associated tools.py can execute arbitrary Python code with the privileges of the workflow runner during execution via WorkflowManager or after load yaml.
Recommendations Update praisonaiagents to version 1.6.78 or later.

Exploit

Fix

RCE

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61437

Affected Products

Praisonaiagents