Description
PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.
Severity (CVSS)
| Base score | 8.5 |
|---|---|
| Severity | High |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-94 — Improper Control of Generation of Code ('Code Injection')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| MervinPraison | PraisonAI | 0 to <4.6.78; 4.6.78 |
References
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-79fv-7hq9-w7xg (vendor-advisory)
- https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0 (patch)
- https://www.vulncheck.com/advisories/praisonai-before-code-injection-via-api-deployment-generator (third-party-advisory)
Generated from the official CVE List on 16 Jul 2026 07:01 UTC.