CVE-2026-61443: Mervinpraison Praisonai
High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.
PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.
Affected products
- Mervinpraison Praisonai: before 1.6.78 (fixed in 1.6.78)
Published 2026-07-15. Last modified 2026-07-15.