CVE-2026-62176: PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation

Published Oct 7, 2026
·
Updated

Summary The deploy/api.py module generates Python server code by directly interpolating the agentsfile parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agentsfile value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code.

Details

src/praisonai/praisonai/deploy/api.py (line 80):

python code = f'''... praisonai = PraisonAI(agentfile="{agentsfile}") ... "agentfile": "{agentsfile}" ...'''

The generated code is then executed (line 190): python subprocess.Popen(['python', serverfile])

agentsfile is never sanitized or validated. A malicious value breaks out of the string context:

python agentsfile = '"); import os; os.system("id"); #' Generated code becomes: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")

The same pattern exists in deploy/docker.py (line 33) for Dockerfile generation.

PoC

python The injection: agentsfile = '"); import os; os.system("id"); #'

What the generated code looks like: template = f'praisonai = PraisonAI(agentfile="{agentsfile}")' print(template) Output: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")

Impact - Arbitrary code execution on the machine running the deploy command - Supply chain risk if agentsfile comes from a configuration file or CI/CD pipeline

Other sources

PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the deploy/api.py module generates Python server code by directly interpolating the agentsfile parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agentsfile value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. Version 4.6.78 patches the issue.

— MITRE

Affected Software

1 affected componentFixes available
pip/PraisonAI<=4.6.77
4.6.78

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/PraisonAI to a version that resolves this vulnerability.

    Fixed in 4.6.78
  2. Upgrade

    Upgrade PraisonAI to a version that resolves this vulnerability.

    Fixed in 4.6.78

Event History

Oct 7, 2026
Advisory Published
via GitHub·04:05 PM
Data Sourced
via GitHub·04:05 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployment paths use the unsafe value?

The deploy/api.py path embeds agents_file into generated Python server code, which is then started with subprocess.Popen(). The deploy/docker.py path uses the same interpolation pattern when generating a Dockerfile.

2

What access does an attacker need to exploit this?

An attacker needs control of the agents_file value. The provided data identifies CLI arguments, configuration, and an upstream API as possible sources of that control.

3

Why does controlling this parameter lead to code execution?

The value is inserted directly into Python string literals without sanitization or validation. A crafted value can terminate the string context and add Python statements before the generated server file is executed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203