VYPR
Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026

PraisonAI before 1.6.78 Remote Code Execution via SkillTools

CVE-2026-61443

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.