CVE-2026-61444 | MervinPraison PraisonAI up to 4.6.77 Code Generator deploy/api.py subprocess.Popen agents_file code injection

SecurityVulns

A vulnerability labeled as critical has been found in MervinPraison PraisonAI up to 4.6.77. Affected by this vulnerability is the function subprocess.Popen of the file deploy/api.py of the component Code Generator. The manipulation of the argument agents_file results in code injection.

This vulnerability is known as CVE-2026-61444. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More