CVE-2026-61447 EXPLOIT
10.0
CRITICAL · CVSS 3.1 · EPSS 2.5% (pctl 84)
Patch early
A public exploit exists.
Description
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 2.49% — more likely to be exploited than 84% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2026-07-11 |
| Last modified | 2026-07-13 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PraisonAI praisonaiagents 1.6.77 - Remote Code Execution | 2026-08-11 |
References
→ the Explorer · watch your stack · NVD