GHSA-g6j7-pffp-8whg: Code Injection
Summary The deploy/api.py module generates Python server code by directly interpolating the agentsfile parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agentsfile value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code.
Details
src/praisonai/praisonai/deploy/api.py (line 80):
python code = f'''... praisonai = PraisonAI(agentfile="{agentsfile}") ... "agentfile": "{agentsfile}" ...'''
The generated code is then executed (line 190): python subprocess.Popen(['python', serverfile])
agentsfile is never sanitized or validated. A malicious value breaks out of the string context:
python agentsfile = '"); import os; os.system("id"); #' Generated code becomes: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")
The same pattern exists in deploy/docker.py (line 33) for Dockerfile generation.
PoC
python The injection: agentsfile = '"); import os; os.system("id"); #'
What the generated code looks like: template = f'praisonai = PraisonAI(agentfile="{agentsfile}")' print(template) Output: praisonai = PraisonAI(agentfile=""); import os; os.system("id"); #")
Impact - Arbitrary code execution on the machine running the deploy command - Supply chain risk if agentsfile comes from a configuration file or CI/CD pipeline
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/PraisonAIto a version that resolves this vulnerability.Fixed in 4.6.78
Event History
Frequently Asked Questions
Which deployment workflows are affected?
The vulnerable interpolation is present in deploy/api.py when generating Python server code and in deploy/docker.py when generating Dockerfile content. Both use the agents_file value without sanitization or validation.
What level of access does an attacker need to exploit this?
An attacker needs control over the agents_file value. The advisory identifies CLI arguments, configuration, and an upstream API as possible sources of attacker-controlled input.
When does injected code execute?
For the API deployment path, the generated Python server file is executed through subprocess.Popen(['python', server_file]). A crafted agents_file value can break out of the generated Python string and cause arbitrary Python code to run.
How can I check whether my deployment path is exposed?
Review whether your use of the deployment API or Docker generation accepts agents_file from CLI input, configuration, or an upstream API. If an untrusted party can influence that value, the described injection path is present.