Описание
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
EPSS
Процентиль: 32%
0.00392
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 9.1
github
около 1 месяца назад
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
EPSS
Процентиль: 32%
0.00392
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-94