LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-61445

Published
CVSS9.9
Severitycritical
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-61445

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-61445.