PT-2026-60137 · Praisonai · Praisonai
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.6.78
Description
The software fails to safely encode deployment configuration values during the generation of Python source code for API servers. This allows attackers to inject arbitrary Python expressions via the
deploy.api.host and agents file configuration parameters, which are then executed when the generated server starts or processes requests.Recommendations
Update PraisonAI to version 4.6.78 or later.
Avoid using the
deploy.api.host and agents file parameters with untrusted input until the update is applied.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai