<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 12:57:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335965</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335965</link>
      <description>EUVD-2026-335965</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335965</guid>
    </item>
    <item>
      <title>fkie_cve-2026-61447</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61447</link>
      <description>&lt;p&gt;PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-61447</guid>
    </item>
    <item>
      <title>GHSA-2xv2-w8cq-5gxw — PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2xv2-w8cq-5gxw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;### Summary
`CodeAgent._execute_python()` executes LLM-generated Python code in a subprocess with the complete parent-process environment (`os.environ.copy()`), zero AST validation, zero import restrictions, and no sandbox enforcement — even when `CodeConfig(sandbox=True)` is explicitly set. This allows an attacker who can influence LLM output (via prompt injection in agent input, tool results, or ingested content) to exfiltrate all environment secrets (API keys, database credentials, cloud tokens) and execute arbitrary code on the host.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/praisonai-agents/praisonaiagents/agent/code_agent.py` (lines 253–308):&lt;/p&gt;
&lt;p&gt;```python
def _execute_python(self, code: str, **kwargs) -&amp;gt; Dict[str, Any]:
    import subprocess
    import time
    import tempfile
    import os&lt;/p&gt;
&lt;p&gt;start_time = time.time()&lt;/p&gt;
&lt;p&gt;# Write code to temp file
    with tempfile.NamedTemporaryFile(mode=&amp;#39;w&amp;#39;, suffix=&amp;#39;.py&amp;#39;, delete=False) as f:
        f.write(code)           # ← No AST validation, no import blocking
        temp_file = f.name&lt;/p&gt;
&lt;p&gt;try:
        # Execute in subprocess (basic sandboxing)
        env = os.environ.copy()             # ← FULL parent environment
        env.update(self._code_config.environment)&lt;/p&gt;
&lt;p&gt;result = subprocess.run(
            [&amp;#34;python&amp;#34;, temp_file],
            capture_output=True,
            text=True,
            timeout=self._code_config.timeout,
            cwd=self._code_config.working_directory,
            env=env                         # ← All secrets expos…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonaiagents&lt;/p&gt;
&lt;p&gt;### Summary
`CodeAgent._execute_python()` executes LLM-generated Python code in a subprocess with the complete parent-process environment (`os.environ.copy()`), zero AST validation, zero import restrictions, and no sandbox enforcement — even when `CodeConfig(sandbox=True)` is explicitly set. This allows an attacker who can influence LLM output (via prompt injection in agent input, tool results, or ingested content) to exfiltrate all environment secrets (API keys, database credentials, cloud tokens) and execute arbitrary code on the host.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/praisonai-agents/praisonaiagents/agent/code_agent.py` (lines 253–308):&lt;/p&gt;
&lt;p&gt;```python
def _execute_python(self, code: str, **kwargs) -&amp;gt; Dict[str, Any]:
    import subprocess
    import time
    import tempfile
    import os&lt;/p&gt;
&lt;p&gt;start_time = time.time()&lt;/p&gt;
&lt;p&gt;# Write code to temp file
    with tempfile.NamedTemporaryFile(mode=&amp;#39;w&amp;#39;, suffix=&amp;#39;.py&amp;#39;, delete=False) as f:
        f.write(code)           # ← No AST validation, no import blocking
        temp_file = f.name&lt;/p&gt;
&lt;p&gt;try:
        # Execute in subprocess (basic sandboxing)
        env = os.environ.copy()             # ← FULL parent environment
        env.update(self._code_config.environment)&lt;/p&gt;
&lt;p&gt;result = subprocess.run(
            [&amp;#34;python&amp;#34;, temp_file],
            capture_output=True,
            text=True,
            timeout=self._code_config.timeout,
            cwd=self._code_config.working_directory,
            env=env                         # ← All secrets expos…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2xv2-w8cq-5gxw</guid>
    </item>
  </channel>
</rss>
