Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-61447EXPLOITEDPATCHED
praisonai · praisonai

PraisonAI before 1.6.78 Remote Code Execution via CodeAgent

Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

Affected Products

VendorProductVersions
praisonaipraisonai0

References

  • https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw(vendor-advisory)
  • https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagent(third-party-advisory)

Related News (2 articles)

Tier C
Exploit-DB1d ago
[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
→ No new info (linked only)
Tier C
VulDB32d ago
CVE-2026-61447 | MervinPraison PraisonAI up to 1.6.77 AST Validation CodeAgent._execute_python injection
→ No new info (linked only)
CVSS 3.17.5 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.6.78
CWECWE-94
PublishedJul 11, 2026
Last enriched32d agov2
Trending Score58
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-47405
PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership
Trending: 4
HIGHCVE-2026-47406
praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR
Trending: 4
NONECVE-2026-61445EXP
PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
Trending: 1
NONECVE-2026-60091EXP
PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url
Trending: 1
CRITICALCVE-2026-61443EXP
PraisonAI before 1.6.78 Remote Code Execution via SkillTools
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 11, 2026
Discovered by ZDM
Jul 11, 2026
Updated: description, affectedVersions, severity, cvssEstimate, activelyExploited
Jul 11, 2026
Actively Exploited
Jul 13, 2026
Patch Available
Jul 13, 2026

Version History

v2
Last enriched 32d ago
v2Tier C32d ago

Updated severity to HIGH, added CVSS estimate of 7.5, and changed exploit availability status.

descriptionaffectedVersionsseveritycvssEstimateactivelyExploited
via VulDB
v132d ago

Initial creation