Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpq9-hwx9-cwgc

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.8

Описание

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.

EPSS

Процентиль: 4%
0.00144
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.8
nvd
около 1 месяца назад

PraisonAI before 4.6.78 fails to safely encode deployment configuration values when generating Python source code for API servers. Attackers can inject arbitrary Python expressions through the deploy.api.host and agents_file configuration parameters that execute when the generated server starts or handles requests.

EPSS

Процентиль: 4%
0.00144
Низкий

8.5 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-94