← Back to browse · API

CVE-2026-61447

Severity
CRITICAL
CVSS
10.0
EPSS
0.02226
Risk score
40.78
CISA KEV
No
PoC
Yes
Published
2026-07-11
Modified
2026-07-13
First seen
2026-08-07
Aliases
EUVD-2026-43182, GHSA-MHGX-W3W5-2RVC
Products
mervinpraison:PraisonAI 0 <1.6.78
Sources
packetstorm 6f30ed70d9cdb4bcc10afa06|CVE-2026-61447
euvd EUVD-2026-43182

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

References