---
id: GHSA-c6pq-cprj-62fw
title: >-
  Duplicate Advisory: PraisonAI: Unsafe Dynamic Module Loading Leads to
  Arbitrary Code Execution via tools.py in AgentFlow
summary: >-
  Duplicate Advisory: PraisonAI: Unsafe Dynamic Module Loading Leads to
  Arbitrary Code Execution via tools.py in AgentFlow
severity: high
cvss: 7.8
cwe:
  - CWE-693
vendor: praisonaiagents
product: praisonaiagents
ecosystem: pip
affected:
  - praisonaiagents <= 1.6.77
published: '2026-07-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:48:48Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-c6pq-cprj-62fw'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4gfv-wg42-7jw5
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61437'
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-tools-py
  - url: 'https://github.com/advisories/GHSA-c6pq-cprj-62fw'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-08T16:52:14.777Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4gfv-wg42-7jw5. This link is maintained to preserve external references.

### Original Description
PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and imports a sibling tools.py from the workflow file's directory via importlib exec_module without sandboxing, ignoring the PRAISONAI_ALLOW_*_TOOLS environment variables. An attacker who controls a workflow file and its sibling tools.py can execute arbitrary Python code with the workflow runner's privileges when the workflow is executed via WorkflowManager or after load_yaml.

## Affected packages

- `praisonaiagents <= 1.6.77`

## Remediation

Refer to the advisory for the patched release.
