- CVSS
- CRITICAL · 10v3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Published
- 2026-07-11
- Weakness
- CWE-94
- Source
- nvd.nist.gov/vuln/detail/CVE-2026-61447
Description
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
References
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2026-61447 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.