PraisonAI Deploy API Server Generation Vulnerable to Code Injection via Unsanitized f-string (CVE-2026-62176)
A newly published GitHub Security Advisory (GHSA-g6j7-pffp-8whg) discloses a code injection vulnerability in PraisonAI, tracked as CVE-2026-62176 with a reported CVSS of 9.1 and a public proof-of-concept.
What happened
According to the advisory, PraisonAI's deploy/api.py builds Python server code by directly interpolating the agents_file parameter into an f-string, which is then written to disk and executed via subprocess.Popen(['python', server_file]). Because agents_file is never sanitized or validated, a value such as '"); import os; os.system("id"); #' breaks out of the string literal and injects arbitrary Python into the generated server file. The advisory notes the same unsanitized-interpolation pattern also exists in deploy/docker.py for Dockerfile generation.
Why it matters
If agents_file is sourced from a CLI argument, a configuration file, or an upstream API call, anyone able to influence that value can achieve arbitrary code execution on the host running the deploy command. The advisory specifically flags supply-chain risk: an agents_file value pulled from a config file or CI/CD pipeline that isn't fully trusted could let an attacker pivot into build or deployment infrastructure.
What defenders should do now
- Identify any PraisonAI deployments and check whether the
deploy/api.pyordeploy/docker.pycode-generation paths are reachable with attacker- or third-party-influencedagents_filevalues (CLI input, config files, CI/CD variables, upstream API responses). - Treat any pipeline that feeds external or lower-trust data into PraisonAI's deploy tooling as high risk until a patched version is available — track the advisory for a fix.
- As a mitigation ahead of a patch, avoid passing untrusted or externally-sourced strings as
agents_file, and review CI/CD configuration for indirect exposure of this parameter. - From a hunting perspective, watch for unexpected child processes spawned from PraisonAI deploy workflows (e.g., a
pythonprocess launching anomalous subprocesses likeos.systemcalls, shell commands, or network activity shortly after a deploy invocation), and review history/logs of generated server and Dockerfile artifacts for injected code resembling the PoC pattern.
This is developing, net-new intel based solely on the GHSA advisory published 2026-10-07; no vendor patch status or further validation is confirmed here. See the original advisory for full technical details: GHSA-g6j7-pffp-8whg.