Mehrere Schwachstellen (CVE-2026-44963, CVE-2026-61447) in Praisonai
⚠️ CVE-Referenzen:
CVE-2026-44963
CVE-2026-61447
Mervinpraison - Praisonai - CRITICAL - CVE-2026-61447.
PraisonAI versions prior to 1.6.78 contain a vulnerability that allows remote code execution through the CodeAgent._execute_python() function. This flaw arises from the lack of AST validation, import restrictions, and sandbox enforcement when executing Python code generated by a large language model (LLM). Malicious actors can use prompt injection techniques to manipulate LLM outputs, potentially exposing sensitive environment variables or executing arbitrary code on affected systems. Remediation through updating to the latest version is crucial to mitigate these security risks.
Quelle: securityvulnerability.io