Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
8.1
CVE-2026-61443EXPLOITEDPATCHED
praisonai · praisonai

PraisonAI before 1.6.78 Remote Code Execution via SkillTools

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

Affected Products

VendorProductVersions
praisonaipraisonai0

References

  • https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c44f-37qr-gw3f(vendor-advisory)
  • https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-skilltools(third-party-advisory)

Related News (1 articles)

Tier C
VulDB28d ago
CVE-2026-61443 | MervinPraison PraisonAI up to 1.6.77 SkillTools.run_skill_script file inclusion
→ No new info (linked only)
CVSS 3.18.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.6.78
CWECWE-22
PublishedJul 15, 2026
Last enriched28d agov2
Trending Score1
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-61447EXP
PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
Trending: 58
HIGHCVE-2026-47405
PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership
Trending: 4
HIGHCVE-2026-47406
praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR
Trending: 4
NONECVE-2026-61445EXP
PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
Trending: 1
NONECVE-2026-60091EXP
PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Patch Available
Jul 15, 2026
Updated: severity, activelyExploited
Jul 15, 2026

Version History

v2
Last enriched 28d ago
v2Tier C28d ago

Updated severity to CRITICAL and noted that there is no exploit available.

severityactivelyExploited
via VulDB
v128d ago

Initial creation