Critical severity9.1NVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
CVE-2026-61444
CVE-2026-61444
Description
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.