← Blog · · df00tech

PraisonAI Deploy API Server Generation Vulnerable to Code Injection via Unsanitized f-string (CVE-2026-62176)

breaking ghsa pip CVE-2026-62176

A newly published GitHub Security Advisory (GHSA-g6j7-pffp-8whg) discloses a code injection vulnerability in PraisonAI, tracked as CVE-2026-62176 with a reported CVSS of 9.1 and a public proof-of-concept.

What happened

According to the advisory, PraisonAI's deploy/api.py builds Python server code by directly interpolating the agents_file parameter into an f-string, which is then written to disk and executed via subprocess.Popen(['python', server_file]). Because agents_file is never sanitized or validated, a value such as '"); import os; os.system("id"); #' breaks out of the string literal and injects arbitrary Python into the generated server file. The advisory notes the same unsanitized-interpolation pattern also exists in deploy/docker.py for Dockerfile generation.

Why it matters

If agents_file is sourced from a CLI argument, a configuration file, or an upstream API call, anyone able to influence that value can achieve arbitrary code execution on the host running the deploy command. The advisory specifically flags supply-chain risk: an agents_file value pulled from a config file or CI/CD pipeline that isn't fully trusted could let an attacker pivot into build or deployment infrastructure.

What defenders should do now

  • Identify any PraisonAI deployments and check whether the deploy/api.py or deploy/docker.py code-generation paths are reachable with attacker- or third-party-influenced agents_file values (CLI input, config files, CI/CD variables, upstream API responses).
  • Treat any pipeline that feeds external or lower-trust data into PraisonAI's deploy tooling as high risk until a patched version is available — track the advisory for a fix.
  • As a mitigation ahead of a patch, avoid passing untrusted or externally-sourced strings as agents_file, and review CI/CD configuration for indirect exposure of this parameter.
  • From a hunting perspective, watch for unexpected child processes spawned from PraisonAI deploy workflows (e.g., a python process launching anomalous subprocesses like os.system calls, shell commands, or network activity shortly after a deploy invocation), and review history/logs of generated server and Dockerfile artifacts for injected code resembling the PoC pattern.

This is developing, net-new intel based solely on the GHSA advisory published 2026-10-07; no vendor patch status or further validation is confirmed here. See the original advisory for full technical details: GHSA-g6j7-pffp-8whg.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.