Loading market data...
← Back to CVE feed

CVE-2026-61433

HIGH CVSS 7.8 View on NVD ↗

Description

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: Jul 15, 2026 12:18 UTC Modified: Jul 15, 2026 19:50 UTC