Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-61445: PraisonAI AICoder Component Allows File Writing and Command Execution
CVE-2026-61445 · published 2 months ago
Summary
PraisonAI's AICoder component has a security flaw that allows attackers to write files anywhere on the system and run commands with high-level permissions through the chat interface. This means sensitive data could be stolen or modified, and system settings could be changed. Update PraisonAI to version 4.6.78 or later to fix this issue.
Original advisory text
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attac...
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.
References
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9mp3-24cc-77...
- https://www.vulncheck.com/advisories/praisonai-before-arbitrary-file-write-and-c...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61445... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-61445 Vendor Advisory
Severity
9.4
Critical
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 9.4 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published11 Jul 2026
Updated27 Sep 2026
First seen11 Jul 2026
Track software like this
Free during beta