CVE-2026-61444 UNKNOWN

CVE-2026-61444

Published: 2026-07-10

Description

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…