CVE-2026-61447: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox...

Added to the CISA Known Exploited Vulnerabilities catalog on 11 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 10.

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environm...

Required action: Review and patch if applicable to your AI infrastructure.