CVE-2026-61444Patch

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 1d ago at 2 mentions (2026-07-10); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-10: 2Mentions · 2026-07-12: 1Patch / Workaround · 2026-07-10: 2Patch / Workaround · 2026-07-12: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-12: 107-1007-12
Signal classification1 categories
Patch
3100.0%
Classification over time
DateTotalLabels
2026-07-102
Patch2
2026-07-121
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-61444 (CVSS 9.1) - Code injection flaw in PraisonAI <4.6.78. Attackers can execute arbitrary Python code via unsanitized agents_file parameter. Patch immediately to v4.6.78+. #CVE #Vulnerability #PatchNow https://t.co/IsEHtCVPIn

    Post summary

    The tweet alerts about a critical code injection vulnerability (CVE-2026-61444) in PraisonAI and urges immediate patching to version 4.6.78+.

    1000054
    71 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-61444 — CVSS 9.1/10 █████████░ PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/znNH4yeVxJ

    Post summary

    A critical code injection vulnerability (CVE‑2026‑61444) was disclosed in PraisonAI versions prior to 4.6.78, with a CVSS of 9.1, and a patch is now available.

    1000098
    65 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - PraisonAI Code Injection via Unsanitized agents_file f-string (CVE-2026-61444) PraisonAI's deploy/api.py interpolates the agents_file parameter directly into an f-string with no sanitization. That string becomes generated server code which is then executed via subprocess.Popen(), so an attacker who controls agents_file can inject arbitrary Python that runs when the generated code executes. The result is full code execution in the context of the PraisonAI deployment process. Per the CVSS vector it requires a privileged/authorized user of the deploy API, with high confidentiality, integrity, and availability impact and a scope change. 👉Upgrade PraisonAI to 4.6.78.

    Post summary

    A critical PraisonAI code‑execution flaw (CVE‑2026‑61444) is disclosed, with a clear patch recommendation to upgrade to 4.6.78 to mitigate the risk.

    0000065
    246 followersView on X

Explore more