Description
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.
Published: 2026-07-11
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PraisonAI before version 4.6.78 contains missing path validation and command sanitization in its AICoder component, allowing attackers to inject malicious prompts through the chat interface to write files to any filesystem location and execute arbitrary shell commands with root privileges.

Affected Systems

The vulnerable versions are all releases of MervinPraison PraisonAI prior to 4.6.78.

Risk and Exploitability

The CVSS score of 9.4 reflects critical severity. EPSS score of < 1% indicates a very low but nonzero exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Attackers with access to the public or privileged chat interface can remotely exploit the flaw, as inferred from the description.

Generated by OpenCVE AI on July 29, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 4.6.78 or later, which implements proper path validation and command sanitization.
  • If a patch cannot be applied immediately, disable the AICoder chat component or restrict access to trusted personnel only.
  • Implement additional input validation or sandboxing around any remaining LLM tool calls to enforce strict path restrictions and prevent shell execution.

Generated by OpenCVE AI on July 29, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Sat, 11 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.
Title PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
First Time appeared Praison
Praison praisonai
Weaknesses CWE-22
CPEs cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*
Vendors & Products Praison
Praison praisonai
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Mervinpraison Praisonai
Praison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T14:34:11.901Z

Reserved: 2026-07-09T14:05:47.929Z

Link: CVE-2026-61445

cve-icon Vulnrichment

Updated: 2026-07-14T14:29:30.359Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')