CVE-2026-60085 UNKNOWN

CVE-2026-60085

Published: 2026-07-15

Description

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write restrictions are completely ignored. Attackers can execute arbitrary subprocess commands, read sensitive files, and perform destructive operations despite explicit security policy configuration.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…