CVE-2026-61444: Mervinpraison Praisonai
Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
Affected products
- Mervinpraison Praisonai: before 4.6.78 (fixed in 4.6.78)
Published 2026-07-10. Last modified 2026-07-10.