CVE-2026-62176: PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation
Summary The deploy/api.py module generates Python server code by directly interpolating the agentsfile parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agentsfile value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code.
Details
src/praisonai/praisonai/deploy/api.py (line 80):
python code = f'''... praisonai = PraisonAI(agentfile="{agentsfile}") ... "agentfile": "{agentsfile}" ...'''
The generated code is then executed (line 190): python subprocess.Popen(['python', serverfile])
agentsfile is never sanitized or validated. A malicious value breaks out of the string context:
python agentsfile = '"); import os; os.system("id"); #' Generated code becomes: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")
The same pattern exists in deploy/docker.py (line 33) for Dockerfile generation.
PoC
python The injection: agentsfile = '"); import os; os.system("id"); #'
What the generated code looks like: template = f'praisonai = PraisonAI(agentfile="{agentsfile}")' print(template) Output: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")
Impact - Arbitrary code execution on the machine running the deploy command - Supply chain risk if agentsfile comes from a configuration file or CI/CD pipeline
Other sources
PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the deploy/api.py module generates Python server code by directly interpolating the agentsfile parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agentsfile value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. Version 4.6.78 patches the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/PraisonAIto a version that resolves this vulnerability.Fixed in 4.6.78 - Upgrade
Upgrade
PraisonAIto a version that resolves this vulnerability.Fixed in 4.6.78
Event History
Frequently Asked Questions
Which deployment paths use the unsafe value?
The deploy/api.py path embeds agents_file into generated Python server code, which is then started with subprocess.Popen(). The deploy/docker.py path uses the same interpolation pattern when generating a Dockerfile.
What access does an attacker need to exploit this?
An attacker needs control of the agents_file value. The provided data identifies CLI arguments, configuration, and an upstream API as possible sources of that control.
Why does controlling this parameter lead to code execution?
The value is inserted directly into Python string literals without sanitization or validation. A crafted value can terminate the string context and add Python statements before the generated server file is executed.