Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
🚨 CVE-2026-61444 — CVSS 9.1/10
█████████░
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file...
Severity: CRITICAL
Patch now.
#cybersecurity#CVE https://t.co/znNH4yeVxJ
Post summary
A critical code injection vulnerability (CVE‑2026‑61444) was disclosed in PraisonAI versions prior to 4.6.78, with a CVSS of 9.1, and a patch is now available.
🚨Critical - PraisonAI Code Injection via Unsanitized agents_file f-string (CVE-2026-61444)
PraisonAI's deploy/api.py interpolates the agents_file parameter directly into an f-string with no sanitization. That string becomes generated server code which is then executed via subprocess.Popen(), so an attacker who controls agents_file can inject arbitrary Python that runs when the generated code executes.
The result is full code execution in the context of the PraisonAI deployment process. Per the CVSS vector it requires a privileged/authorized user of the deploy API, with high confidentiality, integrity, and availability impact and a scope change.
👉Upgrade PraisonAI to 4.6.78.
Post summary
A critical PraisonAI code‑execution flaw (CVE‑2026‑61444) is disclosed, with a clear patch recommendation to upgrade to 4.6.78 to mitigate the risk.