Sceawere
Vulnerability Detail
CVE-2026-62176UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PraisonAI Arbitrary Code Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 1d ago
- Vendor
- MervinPraison
- Product
- PraisonAI
- Attack Type
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_file` value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. Version 4.6.78 patches the issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-10-07T17:16:56.007Z",
"pubdate": "2026-10-07T17:16:56.007Z",
"executiveSummary": "PraisonAI versions prior to 4.6.78 are susceptible to an arbitrary code injection vulnerability located within the deploy/api.py module.\nThe vulnerability stems from improper neutralization of user-supplied input when generating server-side Python code.\nAn attacker capable of influencing the 'agents_file' parameter can achieve remote code execution (RCE) with the privileges of the application process.\nThis flaw is categorized as an improper input validation and injection vulnerability, presenting a critical risk to the confidentiality, integrity, and availability of the host system.\nSuccessful exploitation allows for the execution of arbitrary commands, potentially leading to full system compromise, data exfiltration, or lateral movement within the environment.\nThe vulnerability requires the attacker to have control over the 'agents_file' configuration input, which may be exposed via CLI arguments, external configuration files, or upstream API endpoints.",
"technicalDetails": "The root cause of this vulnerability is the insecure implementation of dynamic Python code generation in the 'deploy/api.py' module of PraisonAI. Specifically, the application utilizes Python f-strings to interpolate the 'agents_file' parameter directly into a string buffer intended for subsequent file creation and execution.\nBecause the input is not sanitized or validated for malicious payloads prior to interpolation, the application is vulnerable to code injection. An attacker can craft a payload containing Python syntax—such as 'os.system()' calls or import statements—that escapes the intended context and is written to a temporary server file.\nThe execution flow involves the following steps: 1) The attacker supplies a malicious string as the 'agents_file' parameter. 2) 'deploy/api.py' concatenates this input directly into a code template using an f-string. 3) The resulting content is written to a file on the filesystem. 4) The application subsequently invokes 'subprocess.Popen()' to execute the newly generated file. 5) The operating system executes the injected code as part of the process, granting the attacker the same execution context as the PraisonAI application.\nThis vulnerability is present in all versions of PraisonAI prior to 4.6.78. The attack does not inherently require authentication to the application if the input vector is reachable via exposed CLI interfaces or unauthenticated API endpoints, effectively lowering the barrier for exploitation.\nPost-exploitation, an attacker can perform arbitrary actions, including installing persistence mechanisms, accessing local environment variables, modifying sensitive project files, or interacting with network resources accessible to the host machine. The lack of input sanitization at the point of ingestion transforms a configuration parameter into a direct execution vector for arbitrary system commands."
}