CVE-2026-61444
MervinPraison PraisonAI
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
- CVSS
- 9.4
- EPSS
- 0.39% 31.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11