---
id: GHSA-mhgx-w3w5-2rvc
title: >-
  Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without
  Sandboxing and Leaks All Environment Secrets
summary: >-
  Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without
  Sandboxing and Leaks All Environment Secrets
severity: critical
cvss: 10
cwe:
  - CWE-94
vendor: praisonai
product: praisonai
ecosystem: pip
affected:
  - praisonai <= 1.6.77
published: '2026-07-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:43:52Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-mhgx-w3w5-2rvc'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61447'
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagent
  - url: 'https://github.com/advisories/GHSA-mhgx-w3w5-2rvc'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-08T16:52:14.780Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2xv2-w8cq-5gxw. This link is maintained to preserve external references.

### Original Description
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

## Affected packages

- `praisonai <= 1.6.77`

## Remediation

Refer to the advisory for the patched release.
