LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-61438

Published
CVSS7.3
Severityhigh
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Description

PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-61438

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-61438.