---
id: CVE-2026-61445
title: >-
  PraisonAI before 4.6.78 contains arbitrary file write and command execution
  vulnerabilities in the AICoder component due to missing path validation and
  command sanitization in LLM tool calls
summary: >-
  PraisonAI before 4.6.78 contains arbitrary file write and command execution
  vulnerabilities in the AICoder component due to missing path validation and
  command sanitization in LLM tool calls. Attackers can inject malicious prompts
  throug…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-22
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61445'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9mp3-24cc-77mg
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-before-arbitrary-file-write-and-command-execution
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-07-11T23:16:21.382Z'
epss: 0.00881
epssPercentile: 0.57631
---

## Overview

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
