Beveiligingsadvies

CVE-2026-61443

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-15 11:25:42
Laatst bijgewerkt 2026-07-15 12:14:45
Toegewezen door VulnCheck
CVSS-score 8.6
Status PUBLISHED

Beschrijving

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.