{"id":"GHSA-qpq9-hwx9-cwgc","title":"Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source","summary":"Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source","severity":"high","cvss":7.8,"cwe":["CWE-94"],"vendor":"praisonai","product":"praisonai","ecosystem":"pip","affected":["praisonai <= 4.6.77"],"published":"2026-07-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T19:36:22Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-qpq9-hwx9-cwgc","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-79fv-7hq9-w7xg"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61433"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-code-injection-via-api-deployment-generator"},{"url":"https://github.com/advisories/GHSA-qpq9-hwx9-cwgc"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-08T20:06:22.195Z","slug":"GHSA-qpq9-hwx9-cwgc","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-79fv-7hq9-w7xg. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.\n\n## Affected packages\n\n- `praisonai <= 4.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}