Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-61447: PraisonAI CodeAgent Python Code Execution Risk

CVE-2026-61447 CVE-2026-61447
Summary

PraisonAI versions prior to 1.6.78 are at risk of attackers executing malicious code on the host system. This is due to a lack of validation and restrictions on Python code generated by the Large Language Model (LLM). To protect your system, update PraisonAI to version 1.6.78 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
mervinpraison praisonai < 1.6.78
Original title
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox...
Original description
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
nvd CVSS3.1 10.0
nvd CVSS4.0 10.0
Vulnerability type
CWE-94 Code Injection
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026