[vulnfeed] 3 critical CVEs — 2026-07-11 16:00 UTC
vulnfeed
Critical alert — 2026-07-11 17:27 UTC
3 new critical CVEs
in the last 5 hours — 3 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-61447CRITICAL
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that exe
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox en
CVSS 10.0
CVE-2026-61445CRITICAL
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder com
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attacker
CVSS 9.4
CVE-2026-60090CRITICAL
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassand
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection
CVSS 9.3
vulnfeed critical alerts — vulnfeed.it.
Unsubscribe
Don't miss what's next. Subscribe to Vulnfeed: