Arbitrary Code Execution Vulnerability in PraisonAI by Mervin Praison
CVE-2026-62176

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-62176?

The PraisonAI multi-agent system prior to version 4.6.78 contains a security flaw related to its deploy/api.py module. This vulnerability arises from the erroneous interpolation of the agents_file parameter in an f-string, allowing an attacker to manipulate this parameter through CLI arguments or API inputs. If exploited, this could enable the execution of arbitrary Python code, posing significant security risks. Users are encouraged to upgrade to version 4.6.78 or later to mitigate this vulnerability.

Affected Version(s)

PraisonAI < 4.6.78

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.