2026-07-11NOTABLEPraisonAI: three critical CVEs, unsandboxed LLM code execution leaks all env secrets, plus tool-call RCE and DDL injection
PraisonAI CodeAgent, unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0)
cve · CVE-2026-61447
Coverage
1
first 2026-07-11 → last 2026-07-11
Latest activity
2026-07-11
PraisonAI: three critical CVEs, unsandboxed LLM code execution leaks all env secrets, plus tool-call RCE and…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, public-sector
Sources cited
7
3 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-61447, newest first. Check the date before acting on an older one.
- Upgrade PraisonAI to praisonaiagents ≥ 1.6.78 and praisonai ≥ 4.6.78 on any self-hosted deployment; all three CVEs are fixed in that release line.2026-07-11CVE-2026-61447 +2
Defender insights
What each entry about CVE-2026-61447 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (4 across 3 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: Unix Shell · Command and Scripting Interpreter: Python
- Credential AccessUnsecured Credentials
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-11/praisonai-agentic-framework-three-cves-code-exec-rce-ddli · ATT&CK page ↗
Execution TA0002
T1059.004Command and Scripting Interpreter: Unix Shell×1
Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.
Evidence: 2026-07-11/praisonai-agentic-framework-three-cves-code-exec-rce-ddli · ATT&CK page ↗
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-07-11/praisonai-agentic-framework-three-cves-code-exec-rce-ddli · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-07-11/praisonai-agentic-framework-three-cves-code-exec-rce-ddli · ATT&CK page ↗
Entries about PraisonAI CodeAgent, unsandboxed LLM-generated Python execution with full env-secret leak (CVSS 10.0) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- PraisonAI×1
- PraisonAI AICoder, arbitrary file write / command execution via LLM tool calls (CVSS 9.4)×1
- PraisonAI PGVector/Cassandra knowledge store, SQL/CQL injection via unvalidated vector dimension (CVSS 9.3)×1
Where this entity is cited
Source distribution
- euvd.enisa.europa.eu3 (43%)
- github.com3 (43%)
- thehackerwire.com1 (14%)
External references
All cited sources (7)
- github.comprimaryPraisonAI / MervinPraison (GitHub Security Advisory)https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw
- github.comprimaryPraisonAI / MervinPraison (GitHub Security Advisory)https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-9mp3-24cc-77mg
- github.comprimaryPraisonAI / MervinPraison (GitHub Security Advisory)https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-wf65-4jjx-q444
- euvd.enisa.europa.euENISA EUVD (EUVD-2026-43175)https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43175
- euvd.enisa.europa.euENISA EUVD (EUVD-2026-43181)https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43181
- euvd.enisa.europa.euENISA EUVD (EUVD-2026-43182)https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-43182
- thehackerwire.comTheHackerWirehttps://www.thehackerwire.com/praisonai-rce-cve-2026-61447/