PraisonAI < 4.6.78 Supply-Chain Threat: Critical Vulnerabilities Confirmed
PraisonAI versions before 4.6.78 are affected by critical supply-chain vulnerabilities that allow arbitrary file writes and command execution with root privileges.
What happened
PraisonAI before 4.6.78 contains multiple critical vulnerabilities tracked as CVE-2026-60090, CVE-2026-61445, and CVE-2026-61447. These vulnerabilities allow attackers to inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute arbitrary shell commands with root privileges. The vulnerabilities exist due to missing path validation, command sanitization, and lack of AST validation, import restrictions, or sandbox enforcement in the AICoder and CodeAgent components.
To assess your exposure, check if you are using PraisonAI version 4.6.78 or later. If not, you are vulnerable to these critical supply-chain attacks. The recommended action is to upgrade to PraisonAI 4.6.78 or later to mitigate the vulnerabilities. For more details, consult the primary sources linked in the threat data.
How 0Day mitigates this
praisonai is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.