No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 13 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 11 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system. | |
| Title | PraisonAI before 1.6.78 Remote Code Execution via CodeAgent | |
| First Time appeared |
Praison
Praison praisonai |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Praison
Praison praisonai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-13T15:21:34.593Z
Reserved: 2026-07-09T14:06:14.016Z
Link: CVE-2026-61447
Updated: 2026-07-13T15:21:10.333Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T06:15:04Z