PT-2026-60133 · Praisonai · Praisonai
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.6.78
Description
The default Subprocess Sandbox backend fails to enforce security policies. Specifically, restrictions defined in
blocked commands, blocked paths, blocked imports, allow subprocess, and allow file write are ignored. This allows attackers to execute arbitrary subprocess commands, read sensitive files, and perform destructive operations regardless of the security policy configuration.Recommendations
Update PraisonAI to version 4.6.78 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai