Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-61447: PraisonAI CodeAgent Python Code Execution Risk
CVE-2026-61447 · published 2 months ago
Summary
PraisonAI versions prior to 1.6.78 are at risk of attackers executing malicious code on the host system. This is due to a lack of validation and restrictions on Python code generated by the Large Language Model (LLM). To protect your system, update PraisonAI to version 1.6.78 or later.
What to do
- Update mervinpraison praisonai to version 1.6.78 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mervinpraison | praisonai | < 1.6.78 |
Original advisory text
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox...
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS 2%
Type
CWE-94Code Injection
Timeline
Published11 Jul 2026
Updated22 Sep 2026
First seen11 Jul 2026
Track software like this
Free during beta