OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-62176: PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation

GitHub Advisories · officialPublished Oct 7, 2026Risk 50/100

### Summary The `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_file` value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. ### Details `src/praisonai/praisonai/deploy/api.py` (line 80): ```python code = f'''... praisonai = PraisonAI(agent_file="{agents_file}") ... "agent_file": "{agents_file}" ...''' ``` The generated code is then executed (line 190): ```python subprocess.Popen(['python', server_file]) ``` `agents_file` is never sanitized or validated. A malicious value breaks out of the string context: ```python agents_file = '"); import os; os.system("id"); #' # Generated code becomes: # praisonai = PraisonAI(agent_file=""); import os; os.system("id"); #") ``` The same pattern exists in `deploy/docker.py` (line 33) for Dockerfile generation. ### PoC ```python # The injection: agents_file = '"); import os; os.system("id"); #' # What the generated code looks like: template = f'praisonai = PraisonAI(agent_file="{agents_file}")' print(template) # Output: praisonai = PraisonAI(agent_file=""); import os; os.system("id"); #") ``` ### Impact - **Arbitrary code execution** on the machine running the deploy command - **Supply chain risk** if `agents_file` comes from a configuration file or CI/CD pipeline

Upgrade affected packages to a patched version: PraisonAI 4.6.78.

Vendor
Not specified
Product
PraisonAI
Exploitation
none known
Evidence
official
CVSS
9.1

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source