PraisonAI Vulnerability Allows Arbitrary Code Execution via Unsafe Module Loading
Article Content
- •CVE-2026-61437 allows arbitrary code execution via unsafe dynamic module loading.
- •Affected users include those using WorkflowManager for untrusted workflows.
- •The vulnerability has a high severity score of 8.5 but is not reported as actively exploited.
A vulnerability identified as CVE-2026-61437 in PraisonAI allows attackers to execute arbitrary Python code by controlling a workflow file and a sibling tools.py file. This flaw arises from unsafe dynamic module loading during workflow execution, specifically in the AgentFlow._resolve_pydantic_class method. Affected users include those utilizing WorkflowManager for workspace discovery or creating workflows from untrusted sources. The vulnerability has a CVSS score of 8.5, indicating a high severity level. It was published on July 10, 2026, and has not been reported as in the wild. Users are advised to review their workflows and apply necessary mitigations to secure their environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-61437 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is CVE-2026-61437?
Who is affected by this vulnerability?
What actions should be taken to mitigate this risk?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…