Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
CVE-2026-61447
Description
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxwmitrevendor-advisory
- www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagentmitrethird-party-advisory
News mentions
0No linked articles in our index yet.