High severity7.5NVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
CVE-2026-60085
CVE-2026-60085
Description
PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.