AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-61437.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 08, 2026

Disclosure summary

### Summary An unsafe dynamic module loading vulnerability allows an attacker who can control a workflow file and a sibling `tools.py` to execute arbitrary Python code when the workflow is executed. ### Details The vulnerability is located in the workflow structured output resolution logic. File: src/praisonai-agents/praisonaiagents/workflows/workflows.py Method: AgentFlow._resolve_pydantic_class ```python if self.file_path: workflow_dir = Path(self.file_path).parent tools_path = workflow_dir / "tools.py" if tools_path.exists(): spec = importlib.util.spec_from_file_location("tools", tools_path) tools_module = importlib.util.module_from_spec(spec) spec.loader.exec_module(tools_module) # Arbitrary code execution ``` This code is reached during step execution when a step uses a string `output_pydantic`: ```python step_output_pydantic = getattr(step, '_output_pydantic', None) if step_output_pydantic and isinstance(step_output_pydantic, str): resolved_class = self._resolve_pydantic_class(step_output_pydantic) ``` `file_path` is set automatically by: - `WorkflowManager._load_workflow()` (used by workspace discovery) - `WorkflowManager.create_workflow()` It can also be set manually after

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-4gfv-wg42-7jw5

Open original source · Updated Oct 08, 2026

PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
pippraisonaiagents1.6.78

Original records & references

PUBLISHED 2026-10-08T12:48:57-04:00
MODIFIED 2026-10-08T12:48:58-04:00
INGESTED 2026-10-10T20:25:13-04:00