Critical severity9.1GHSA Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-62176
CVE-2026-62176
Description
PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the deploy/api.py module generates Python server code by directly interpolating the agents_file parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agents_file value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. Version 4.6.78 patches the issue.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.