GHSA-g6j7-pffp-8whg: Code Injection

Published Oct 7, 2026
·
Updated

Summary The deploy/api.py module generates Python server code by directly interpolating the agentsfile parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agentsfile value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code.

Details

src/praisonai/praisonai/deploy/api.py (line 80):

python code = f'''... praisonai = PraisonAI(agentfile="{agentsfile}") ... "agentfile": "{agentsfile}" ...'''

The generated code is then executed (line 190): python subprocess.Popen(['python', serverfile])

agentsfile is never sanitized or validated. A malicious value breaks out of the string context:

python agentsfile = '"); import os; os.system("id"); #' Generated code becomes: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")

The same pattern exists in deploy/docker.py (line 33) for Dockerfile generation.

PoC

python The injection: agentsfile = '"); import os; os.system("id"); #'

What the generated code looks like: template = f'praisonai = PraisonAI(agentfile="{agentsfile}")' print(template) Output: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")

Impact - Arbitrary code execution on the machine running the deploy command - Supply chain risk if agentsfile comes from a configuration file or CI/CD pipeline

Affected Software

1 affected componentFixes available
pip/PraisonAI<=4.6.77
4.6.78

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/PraisonAI to a version that resolves this vulnerability.

    Fixed in 4.6.78

Event History

Oct 7, 2026
Advisory Published
via GitHub·04:05 PM
Data Sourced
via GitHub·04:05 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployment workflows are affected?

The vulnerable interpolation is present in deploy/api.py when generating Python server code and in deploy/docker.py when generating Dockerfile content. Both use the agents_file value without sanitization or validation.

2

What level of access does an attacker need to exploit this?

An attacker needs control over the agents_file value. The advisory identifies CLI arguments, configuration, and an upstream API as possible sources of attacker-controlled input.

3

When does injected code execute?

For the API deployment path, the generated Python server file is executed through subprocess.Popen(['python', server_file]). A crafted agents_file value can break out of the generated Python string and cause arbitrary Python code to run.

4

How can I check whether my deployment path is exposed?

Review whether your use of the deployment API or Docker generation accepts agents_file from CLI input, configuration, or an upstream API. If an untrusted party can influence that value, the described injection path is present.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203