← Volver al buscador de CVEs

CVE-2026-61447

PraisonAI

Descripción

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

CVSS 10EPSS 0.742%Riesgo 1.07
Ver fuente
Publicación
2026-07-11 14:16:23
Versiones afectadas
<1.6.78
Tipo
Software crítico
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H