Security Advisory

CVE-2026-61443

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-15 11:25:42
Last updated 2026-07-15 12:14:45
Assigner VulnCheck
CVSS score 8.6
State PUBLISHED

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.