Junglewise Threat Intelligence

CVE-2026-61438: MervinPraison PraisonAI remote code execution in JobWorkflowExecutor

CVE-2026-61438 · Severity: high · CVSS 7.3 · Published 2026-07-15

Vendors: MervinPraison.

Executive brief

PraisonAI, an AI agent framework, is vulnerable to a security flaw that allows the execution of unauthorized commands. By providing a specially crafted workflow file, an attacker can bypass the software's safety checks to run arbitrary code on the host system. This could lead to a full system compromise, data theft, or unauthorized access to corporate resources, especially in environments where AI workflows are shared or automated.

Technical details

A remote code execution vulnerability exists in PraisonAI's JobWorkflowExecutor._exec_inline_python() function due to a broken Abstract Syntax Tree (AST) sandbox. While the application attempts to restrict Python execution by checking AST nodes against an allowlist and limiting builtins, it explicitly permits the 'os' module in its allowed_modules list. An attacker can exploit this by creating a YAML workflow file containing 'import os' followed by dangerous calls such as 'os.system()'. When a user or CI/CD pipeline executes this malicious workflow, the commands run with the full privileges of the calling process. The issue is addressed in version 4.6.78 by tightening module validation.

Affected products

  • MervinPraison PraisonAI < 4.6.78

Timeline

  • 2026-06-25: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: NVD publication date

References