VYPR
Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026

PraisonAI before 1.6.78 Remote Code Execution via CodeAgent

CVE-2026-61447

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.