CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-61445: praisonai <= 4.6.77

CVE-2026-61445 affects praisonai. CVSS 3.1 base score 9.9 (GitHub Advisory Database). EPSS 0.00881 (percentile 0.57891), scored 2026-10-08. Affected range: <= 4.6.77. Fixed version: 4.6.78.

Affected technology

praisonai · <= 4.6.77
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (GitHub Advisory Database, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An attacker can achieve arbitrary file write to any location on the filesystem (including `/root/.ssh/authorized_keys`, `/etc/crontab`) and arbitrary command execution through prompt injection in the chat interface. GitHub Advisory Database’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high.

Published

Product
praisonai
CCR priority
39.8 /100 (P4)
CVSS 3.1
9.9 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H · GitHub Advisory Database
EPSS
0.00881 · percentile 0.57891 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-61445.html