← Volver al buscador de CVEs

CVE-2026-61438

PraisonAI

Descripción

PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.

CVSS 7.3EPSS 0.202%Riesgo 0.74
Ver fuente
Publicación
2026-07-15 12:18:18
Versiones afectadas
<4.6.78
Tipo
Software crítico
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H