A critical remote code execution flaw, CVE-2026-61447, was disclosed in the PraisonAI AI agent framework, affecting versions before 1.6.78. The vulnerability lies in CodeAgent._execute_python(), which executes LLM-generated Python without AST validation, import restrictions, or sandbox enforcement, allowing attackers to use prompt injection to make the agent run arbitrary code on the host. The issue received the maximum severity rating of CVSS 10.0 under both v3.1 and v4.0.
Successful exploitation can result in full host compromise and theft of sensitive data, including API keys, cloud credentials, database passwords, and other environment secrets, with potential pivoting into connected services. PraisonAI 1.6.78 fixes the issue, and defenders are being urged to upgrade immediately, reduce network exposure, rotate potentially exposed secrets, and monitor for anomalous outbound connections; no confirmed in-the-wild exploitation had been reported at disclosure time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-11, CVE-2026-61447 was publicly disclosed as a critical remote code execution vulnerability in PraisonAI affecting versions prior to 1.6.78. The flaw allows prompt injection to influence LLM-generated Python code execution, potentially leading to arbitrary code execution and theft of environment secrets.
PraisonAI version 1.6.78 was identified as the fixed release for a critical remote code execution vulnerability in CodeAgent._execute_python() affecting versions before 1.6.78. The remediation guidance was to upgrade to 1.6.78 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.