CVE-2026-61444: PraisonAI before 4.6.78 Code Injection via f-string
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agentsfile parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PraisonAIto a version that resolves this vulnerability.Fixed in 4.6.78
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61444?
The severity of CVE-2026-61444 is critical with a score of 9.4.
How do I fix CVE-2026-61444?
To fix CVE-2026-61444, upgrade to PraisonAI version 4.6.78 or later.
What types of vulnerabilities are associated with CVE-2026-61444?
CVE-2026-61444 is associated with code injection vulnerabilities.
What can attackers do with CVE-2026-61444?
Attackers can inject arbitrary Python code that executes when the server code runs.
Which versions of PraisonAI are affected by CVE-2026-61444?
Versions of PraisonAI before 4.6.78 are affected by CVE-2026-61444.