Skip to content
PraisonAI Vulnerability Allows Arbitrary Code Execution via Unsafe Module Loading

PraisonAI Vulnerability Allows Arbitrary Code Execution via Unsafe Module Loading

First seen 9 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 17:38 UTC
  • •CVE-2026-61437 allows arbitrary code execution via unsafe dynamic module loading.
  • •Affected users include those using WorkflowManager for untrusted workflows.
  • •The vulnerability has a high severity score of 8.5 but is not reported as actively exploited.

A vulnerability identified as CVE-2026-61437 in PraisonAI allows attackers to execute arbitrary Python code by controlling a workflow file and a sibling tools.py file. This flaw arises from unsafe dynamic module loading during workflow execution, specifically in the AgentFlow._resolve_pydantic_class method. Affected users include those utilizing WorkflowManager for workspace discovery or creating workflows from untrusted sources. The vulnerability has a CVSS score of 8.5, indicating a high severity level. It was published on July 10, 2026, and has not been reported as in the wild. Users are advised to review their workflows and apply necessary mitigations to secure their environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-10
CVE-2026-61437 published
PraisonAI vulnerability disclosed, allowing arbitrary code execution through unsafe module loading.
Advisories.Gitlab

More articles in this cluster (5)

Following this threat?

Track CVE-2026-61437 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-61437?
CVE-2026-61437 is a vulnerability in PraisonAI that allows arbitrary code execution due to unsafe dynamic module loading.
Who is affected by this vulnerability?
Users of PraisonAI's WorkflowManager who load workflows from untrusted sources are affected.
What actions should be taken to mitigate this risk?
Users should review their workflows and restrict the execution of untrusted code to prevent exploitation.