Critical severity10.0NVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
CVE-2026-61447
CVE-2026-61447
Description
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.