What happened
Verified directly against the GitHub Security Advisory (fetched): the deploy path generates Python server code by interpolating agent_file into an f-string and executing it via subprocess.Popen() with no sanitization. NVD published CVE-2026-62176 (CVSS 9.1) on 2026-10-07. A companion flaw (CVE-2026-62179, CVSS 6.5) covers an authorization issue in the praisonai-platform dependency-deletion endpoint.
Why it matters
PraisonAI is a multi-agent teams framework; code injection in its deployment/CI path means a poisoned agent config (e.g., a malicious agents file pulled from an upstream repo or chat artifact) executes arbitrary code on the deploy host — turning agent definition files into a code-execution attack surface.
Attack vector
The deploy/api.py module interpolates the agents_file parameter into an f-string written to a Python server file and executed via subprocess.Popen(). A malicious agents_file value containing Python expression/payload escapes the string context and injects arbitrary code run as the deploy user; the same pattern exists in Dockerfile generation.
Affected systems
PraisonAI < 4.6.78 (deploy/api.py and deploy/docker.py)
Mitigation
Upgrade PraisonAI to 4.6.78 or later (GitHub Security Advisory GHSA-g6j7-pffp-8whg); sanitize/validate agent_file inputs in CI/CD pipelines.