CVE WATCH / VULNERABILITY DETAIL
CVE-2026-62176
CRITICALCVSS 9.1NVD feed
Published 7 October 2026 · tracked since 8 October 2026
Description
PraisonAI is a multi-agent teams system. Prior to version 4.6.78, the `deploy/api.py` module generates Python server code by directly interpolating the `agents_file` parameter into an f-string that is then written to a file and executed via `subprocess.Popen()`. An attacker who controls the `agents_
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-76470 HIGH 8.8
- CVE-2026-76471 CRITICAL 9.8
- CVE-2026-76464 CRITICAL 9.6
- CVE-2026-76465 CRITICAL 9.8
- CVE-2026-76467 HIGH 7.5
- CVE-2026-76468 HIGH 8.2
- CVE-2026-76469 HIGH 7.4
- CVE-2026-76457 HIGH 8.6
- CVE-2026-76458 HIGH 8.6
- CVE-2026-76459 HIGH 8.8