CVE-2026-61447: Mervinpraison Praisonai
Critical severity, CVSS 10.0. EPSS: 2.5% chance of exploitation in the next 30 days.
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
Affected products
- Mervinpraison Praisonai: before 1.6.78 (fixed in 1.6.78)
Published 2026-07-11. Last modified 2026-07-13.