PT-2026-60137 · Praisonai · Praisonai

·

CVE-2026-61433

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.78
Description The software fails to safely encode deployment configuration values during the generation of Python source code for API servers. This allows attackers to inject arbitrary Python expressions via the deploy.api.host and agents file configuration parameters, which are then executed when the generated server starts or processes requests.
Recommendations Update PraisonAI to version 4.6.78 or later. Avoid using the deploy.api.host and agents file parameters with untrusted input until the update is applied.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61433
GHSA-79FV-7HQ9-W7XG

Affected Products

Praisonai