PT-2026-60133 · Praisonai · Praisonai

·

CVE-2026-60085

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.78
Description The default Subprocess Sandbox backend fails to enforce security policies. Specifically, restrictions defined in blocked commands, blocked paths, blocked imports, allow subprocess, and allow file write are ignored. This allows attackers to execute arbitrary subprocess commands, read sensitive files, and perform destructive operations regardless of the security policy configuration.
Recommendations Update PraisonAI to version 4.6.78 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60085
GHSA-5R6C-GJ4G-R697

Affected Products

Praisonai