CVE-2026-61444: Mervinpraison Praisonai

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().

Affected products

Published 2026-07-10. Last modified 2026-07-10.