Skip to content
COOEY

EXPOSURES › CVE-2026-61444

CVE-2026-61444

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-10 CVSS9.1 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-61444 ↗
⚡ RCE ◐ ZERO-DAY SHAME 85/100 rceunpatchedexploited-in-wildzero-day

PraisonAI's AI deployment platform allows remote code execution via unsanitized user input in version 4.6.78 and below.

A critical code injection flaw in PraisonAI's deploy/api.py allows attackers to execute arbitrary Python code via unsanitized f-string interpolation. This poses a severe risk to DIB organizations relying on AI infrastructure, as it enables remote compromise of the underlying server environment. Immediate patching to version 4.6.78 is required to mitigate this high-severity vulnerability.

Shame score — Critical RCE vulnerability in an AI platform used by defense contractors, indicating a failure in input sanitization and potentially negligent security practices.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.