{"data":{"id":"3ecb90e1-9aa7-41eb-9458-b5382750dffe","title":"GHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls","summary":"The AICoder UI component in PraisonAI exposes write_to_file and execute_command tools to the LLM without path validation or command sanitization. Through prompt injection in the chat interface, an attacker can write to arbitrary filesystem locations, such as /root/.ssh/authorized_keys or /etc/crontab, and execute arbitrary shell commands. Docker containers run as root, which increases the impact.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-9mp3-24cc-77mg","publishedAt":"2026-10-08T22:00:40.000Z","cveId":"CVE-2026-61445","cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":["prompt_injection","other"],"issueType":"vulnerability","affectedPackages":["praisonai@<= 4.6.77 (fixed: 4.6.78)"],"affectedPackageNames":["praisonai"],"affectedVendors":[],"affectedVendorsRaw":["PraisonAI","AICoder"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00881,"epssCheckedAt":"2026-10-10T03:00:40.530Z","kevDateAdded":null,"advisoryAliases":["GHSA-9mp3-24cc-77mg"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T22:00:40.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":["AML.T0051"]}}