{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/praisonai--4.6.77/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PraisonAI (\u003c= 4.6.77)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PraisonAI"],"content_html":"\u003cp\u003ePraisonAI, a framework for AI agent orchestration, contains a critical security vulnerability (CVE-2026-62176) allowing for arbitrary code execution. The vulnerability exists within the \u003ccode\u003edeploy/api.py\u003c/code\u003e and \u003ccode\u003edeploy/docker.py\u003c/code\u003e modules. The application generates Python server code and Dockerfiles using f-string interpolation to insert the \u003ccode\u003eagents_file\u003c/code\u003e parameter directly into template strings without validation or sanitization.\u003c/p\u003e\n\u003cp\u003eAn attacker who can influence the \u003ccode\u003eagents_file\u003c/code\u003e parameter - via CLI arguments, malicious configuration files, or upstream API input - can break out of the string literal context to inject arbitrary Python code. This injected code is subsequently executed when the generated Python script is invoked via \u003ccode\u003esubprocess.Popen()\u003c/code\u003e or when the Docker build process is initiated. The impact includes full command execution on the host machine running the deployment or build process, posing a significant risk to CI/CD pipelines and local development environments. This affects all versions up to and including 4.6.77.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target PraisonAI instance or build pipeline that consumes an untrusted \u003ccode\u003eagents_file\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious \u003ccode\u003eagents_file\u003c/code\u003e string containing a payload designed to close the existing f-string and inject Python commands (e.g., \u003ccode\u003e\u0026quot;); import os; os.system(\u0026quot;id\u0026quot;); #\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker triggers the deployment process (e.g., via a CLI command, API request, or by submitting a malicious repository configuration).\u003c/li\u003e\n\u003cli\u003ePraisonAI's \u003ccode\u003edeploy/api.py\u003c/code\u003e or \u003ccode\u003edeploy/docker.py\u003c/code\u003e script reads the malicious input.\u003c/li\u003e\n\u003cli\u003eThe vulnerability in the module interpolates the payload into a string template, resulting in a malformed Python script containing the attacker's commands.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esubprocess.Popen()\u003c/code\u003e function is called to execute the generated server file.\u003c/li\u003e\n\u003cli\u003eThe operating system executes the Python script, triggering the injected shell commands with the privileges of the PraisonAI process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on the underlying host system. This could lead to full system compromise, exfiltration of credentials or sensitive data, and persistent access within a build environment if the target is an automated CI/CD pipeline.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade PraisonAI to a version later than 4.6.77 immediately.\u003c/li\u003e\n\u003cli\u003eImplement input validation for any user-provided path or file parameters used in deployment or configuration scripts.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD pipelines for configurations that allow external input to influence the \u003ccode\u003eagents_file\u003c/code\u003e parameter in PraisonAI tasks.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T16:57:36Z","date_published":"2026-10-07T16:57:36Z","id":"https://feed.craftedsignal.io/briefs/2026-10-praisonai-rce/","summary":"PraisonAI versions 4.6.77 and earlier are vulnerable to arbitrary code execution via command injection in the deploy/api.py and deploy/docker.py modules due to unsanitized f-string interpolation.","title":"Command Injection in PraisonAI Deployment API and Docker Generation","url":"https://feed.craftedsignal.io/briefs/2026-10-praisonai-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - PraisonAI (\u003c= 4.6.77)","version":"https://jsonfeed.org/version/1.1"}