Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhgx-w3w5-2rvc

Опубликовано: 11 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

EPSS

Процентиль: 81%
0.02226
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 10
nvd
около 1 месяца назад

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.

EPSS

Процентиль: 81%
0.02226
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-94