Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-61443

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

EPSS

Процентиль: 40%
0.00499
Низкий

8.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
github
около 1 месяца назад

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

EPSS

Процентиль: 40%
0.00499
Низкий

8.1 High

CVSS3

Дефекты

CWE-22