Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-61445EXPLOITEDPATCHED
praisonai · praisonai

PraisonAI before 4.6.78 Arbitrary File Write and Command Execution

Description

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.

Affected Products

VendorProductVersions
praisonaipraisonai0

References

  • https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9mp3-24cc-77mg(vendor-advisory)
  • https://www.vulncheck.com/advisories/praisonai-before-arbitrary-file-write-and-command-execution(third-party-advisory)

Related News (1 articles)

Tier C
VulDB32d ago
CVE-2026-61445 | MervinPraison PraisonAI up to 4.6.77 AICoder os command injection
→ No new info (linked only)
CVSS 3.19.9 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
4.6.78
CWECWE-22
PublishedJul 11, 2026
Last enriched32d agov2
Trending Score1
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-61447EXP
PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
Trending: 58
HIGHCVE-2026-47405
PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership
Trending: 4
HIGHCVE-2026-47406
praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR
Trending: 4
NONECVE-2026-60091EXP
PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url
Trending: 1
CRITICALCVE-2026-61443EXP
PraisonAI before 1.6.78 Remote Code Execution via SkillTools
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 11, 2026
Discovered by ZDM
Jul 11, 2026
Updated: affectedVersions, severity, activelyExploited
Jul 11, 2026
Actively Exploited
Jul 14, 2026
Patch Available
Jul 14, 2026

Version History

v2
Last enriched 32d ago
v2Tier C32d ago

Updated affected versions to 4.6.77, changed severity to HIGH, and noted that there is no available exploit.

affectedVersionsseverityactivelyExploited
via VulDB
v132d ago

Initial creation