The deploy/api.py module generates Python server code by directly interpolating the agents_file parameter into an f-string that is then written to a file and executed via subprocess.Popen(). An attacker who controls the agents_file value (via CLI argument, configuration, or upstream API) can inject arbitrary Python code.
src/praisonai/praisonai/deploy/api.py (line 80):
code = f'''...
praisonai = PraisonAI(agent_file="{agents_file}")
...
"agent_file": "{agents_file}"
...'''
The generated code is then executed (line 190):
subprocess.Popen(['python', server_file])
agents_file is never sanitized or validated. A malicious value breaks out of the string context:
agents_file = '"); import os; os.system("id"); #'
# Generated code becomes:
# praisonai = PraisonAI(agent_file=""); import os; os.system("id"); #")
The same pattern exists in deploy/docker.py (line 33) for Dockerfile generation.
# The injection:
agents_file = '"); import os; os.system("id"); #'
# What the generated code looks like:
template = f'praisonai = PraisonAI(agent_file="{agents_file}")'
print(template)
# Output: praisonai = PraisonAI(agent_file=""); import os; os.system("id"); #")
agents_file comes from a configuration file or CI/CD pipeline{
"cwe_ids": [
"CWE-94"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T16:05:53Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}