Security Advisory

CVE-2026-61447

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-11 13:01:05
Last updated 2026-07-13 15:21:34
Assigner VulnCheck
CVSS score 10.0
State PUBLISHED

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.