Arbitrary Code Execution Vulnerability in PraisonAI by Mervin Praison
CVE-2026-62176
9.1CRITICAL
What is CVE-2026-62176?
The PraisonAI multi-agent system prior to version 4.6.78 contains a security flaw related to its deploy/api.py module. This vulnerability arises from the erroneous interpolation of the agents_file parameter in an f-string, allowing an attacker to manipulate this parameter through CLI arguments or API inputs. If exploited, this could enable the execution of arbitrary Python code, posing significant security risks. Users are encouraged to upgrade to version 4.6.78 or later to mitigate this vulnerability.
Affected Version(s)
PraisonAI < 4.6.78
