<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PraisonAI (&lt;= 4.6.77) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/praisonai--4.6.77/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:57:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/praisonai--4.6.77/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in PraisonAI Deployment API and Docker Generation</title><link>https://feed.craftedsignal.io/briefs/2026-10-praisonai-rce/</link><pubDate>Wed, 07 Oct 2026 16:57:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-praisonai-rce/</guid><description>PraisonAI versions 4.6.77 and earlier are vulnerable to arbitrary code execution via command injection in the deploy/api.py and deploy/docker.py modules due to unsanitized f-string interpolation.</description><content:encoded><![CDATA[<p>PraisonAI, a framework for AI agent orchestration, contains a critical security vulnerability (CVE-2026-62176) allowing for arbitrary code execution. The vulnerability exists within the <code>deploy/api.py</code> and <code>deploy/docker.py</code> modules. The application generates Python server code and Dockerfiles using f-string interpolation to insert the <code>agents_file</code> parameter directly into template strings without validation or sanitization.</p>
<p>An attacker who can influence the <code>agents_file</code> parameter - via CLI arguments, malicious configuration files, or upstream API input - can break out of the string literal context to inject arbitrary Python code. This injected code is subsequently executed when the generated Python script is invoked via <code>subprocess.Popen()</code> or when the Docker build process is initiated. The impact includes full command execution on the host machine running the deployment or build process, posing a significant risk to CI/CD pipelines and local development environments. This affects all versions up to and including 4.6.77.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies a target PraisonAI instance or build pipeline that consumes an untrusted <code>agents_file</code> parameter.</li>
<li>The attacker crafts a malicious <code>agents_file</code> string containing a payload designed to close the existing f-string and inject Python commands (e.g., <code>&quot;); import os; os.system(&quot;id&quot;); #</code>).</li>
<li>The attacker triggers the deployment process (e.g., via a CLI command, API request, or by submitting a malicious repository configuration).</li>
<li>PraisonAI's <code>deploy/api.py</code> or <code>deploy/docker.py</code> script reads the malicious input.</li>
<li>The vulnerability in the module interpolates the payload into a string template, resulting in a malformed Python script containing the attacker's commands.</li>
<li>The <code>subprocess.Popen()</code> function is called to execute the generated server file.</li>
<li>The operating system executes the Python script, triggering the injected shell commands with the privileges of the PraisonAI process.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution on the underlying host system. This could lead to full system compromise, exfiltration of credentials or sensitive data, and persistent access within a build environment if the target is an automated CI/CD pipeline.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade PraisonAI to a version later than 4.6.77 immediately.</li>
<li>Implement input validation for any user-provided path or file parameters used in deployment or configuration scripts.</li>
<li>Audit CI/CD pipelines for configurations that allow external input to influence the <code>agents_file</code> parameter in PraisonAI tasks.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>