CVE-2026-61445: PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attac...

Added to the CISA Known Exploited Vulnerabilities catalog on 11 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.9.

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem ...

Required action: Review and patch if applicable to your AI infrastructure.