CVE-2026-62176 | MervinPraison PraisonAI up to 4.6.77 Deploy API api.py subprocess.Popen agents_file code injection

SecurityVulns

A vulnerability marked as problematic has been reported in MervinPraison PraisonAI up to 4.6.77. The affected element is the function subprocess.Popen of the file src/praisonai/praisonai/deploy/api.py of the component Deploy API. This manipulation of the argument agents_file causes code injection.

The identification of this vulnerability is CVE-2026-62176. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More