PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.
References
Configurations
No configuration.
History
15 Jul 2026, 12:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 12:18
Updated : 2026-07-15 19:50
NVD link : CVE-2026-61433
Mitre link : CVE-2026-61433
CVE.ORG link : CVE-2026-61433
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
