{"id":"GHSA-mhgx-w3w5-2rvc","title":"Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets","summary":"Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets","severity":"critical","cvss":10,"cwe":["CWE-94"],"vendor":"praisonai","product":"praisonai","ecosystem":"pip","affected":["praisonai <= 1.6.77"],"published":"2026-07-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:43:52Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-mhgx-w3w5-2rvc","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61447"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagent"},{"url":"https://github.com/advisories/GHSA-mhgx-w3w5-2rvc"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-08T16:52:14.780Z","slug":"GHSA-mhgx-w3w5-2rvc","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-2xv2-w8cq-5gxw. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.\n\n## Affected packages\n\n- `praisonai <= 1.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}