Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh3g-555w-f82q

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 7.3

Описание

PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.

PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.

EPSS

Процентиль: 10%
0.00202
Низкий

7 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 месяца назад

PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.

EPSS

Процентиль: 10%
0.00202
Низкий

7 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-78