<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T12:57:15.746261+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335965</id>
    <title>EUVD-2026-335965</title>
    <updated>2026-10-10T12:57:15.748660+00:00</updated>
    <content>EUVD-2026-335965</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335965"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61447</id>
    <title>fkie_cve-2026-61447</title>
    <updated>2026-10-10T12:57:15.748690+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61447"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2xv2-w8cq-5gxw</id>
    <title>GHSA-2xv2-w8cq-5gxw — PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets</title>
    <updated>2026-10-10T12:57:15.748721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonaiagents</p>
<p>### Summary
`CodeAgent._execute_python()` executes LLM-generated Python code in a subprocess with the complete parent-process environment (`os.environ.copy()`), zero AST validation, zero import restrictions, and no sandbox enforcement — even when `CodeConfig(sandbox=True)` is explicitly set. This allows an attacker who can influence LLM output (via prompt injection in agent input, tool results, or ingested content) to exfiltrate all environment secrets (API keys, database credentials, cloud tokens) and execute arbitrary code on the host.</p>
<p>### Details</p>
<p>`src/praisonai-agents/praisonaiagents/agent/code_agent.py` (lines 253–308):</p>
<p>```python
def _execute_python(self, code: str, **kwargs) -&gt; Dict[str, Any]:
    import subprocess
    import time
    import tempfile
    import os</p>
<p>start_time = time.time()</p>
<p># Write code to temp file
    with tempfile.NamedTemporaryFile(mode='w', suffix='.py', delete=False) as f:
        f.write(code)           # ← No AST validation, no import blocking
        temp_file = f.name</p>
<p>try:
        # Execute in subprocess (basic sandboxing)
        env = os.environ.copy()             # ← FULL parent environment
        env.update(self._code_config.environment)</p>
<p>result = subprocess.run(
            ["python", temp_file],
            capture_output=True,
            text=True,
            timeout=self._code_config.timeout,
            cwd=self._code_config.working_directory,
            env=env                         # ← All secrets expos…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2xv2-w8cq-5gxw"/>
  </entry>
</feed>
