GHSA-qpq9-hwx9-cwgcHigh· 7.8▾ TwilightDuplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-79fv-7hq9-w7xg. This link is maintained to preserve external references.
PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61433High· 7.8PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
GHSA-w37c-cq55-frjpMedium· 5.5Duplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-61431Medium· 5.5PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
GHSA-mhgx-w3w5-2rvcCritical· 10.0Duplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets
CVE-2026-62176Critical· 9.1PraisonAI is a multi-agent teams system
CVE-2026-57131Critical· 9.8PraisonAI is a multi-agent teams system