CVE-2026-61445
Critical · CVSS 9.9PraisonAI — Path Traversal Arbitrary File Write and OS Command Injection RCE via LLM Prompt Injection
- CVSS
- 9.9
- nvd
- EPSS
- 0.54%
- 42th pct
- KEV
- No
- Class
- oss containerizable
- CWE-22
Description
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.
Search profile — drives PoC discovery
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-14T00:00:21.000Z · profiled 2026-07-14T00:30:21.000Z