VYPR
Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026

PraisonAI before 4.6.78 Code Injection via f-string

CVE-2026-61444

Description

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.