Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-61445: PraisonAI AICoder Component Allows File Writing and Command Execution
CVE-2026-61445
Summary
PraisonAI's AICoder component has a security flaw that allows attackers to write files anywhere on the system and run commands with high-level permissions through the chat interface. This means sensitive data could be stolen or modified, and system settings could be changed. Update PraisonAI to version 4.6.78 or later to fix this issue.
Original title
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attac...
Original description
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.
nvd CVSS3.1
9.9
nvd CVSS4.0
9.4
Vulnerability type
CWE-22
Path Traversal
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026