peter bassill · operator
$ cve CVE-2026-61447 JSON

CVE-2026-61447 EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS2.49% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2026-07-11
Last modified2026-07-13

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD