PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 11 Jul 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mervinpraison
Mervinpraison praisonai |
|
| Vendors & Products |
Mervinpraison
Mervinpraison praisonai |
Sat, 11 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges. | |
| Title | PraisonAI before 4.6.78 Arbitrary File Write and Command Execution | |
| First Time appeared |
Praison
Praison praisonai |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Praison
Praison praisonai |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-11T13:01:04.470Z
Updated: 2026-07-14T14:34:11.901Z
Reserved: 2026-07-09T14:05:47.929Z
Link: CVE-2026-61445
Updated: 2026-07-14T14:29:30.359Z
Status : Deferred
Published: 2026-07-11T14:16:23.240
Modified: 2026-07-14T15:17:08.617
Link: CVE-2026-61445
No data.