{
  "feed_version": "1.0",
  "title": "ARETIQ Daily Vulnerability Bulletin",
  "description": "Curated daily digest of high-priority vulnerabilities.",
  "home_page_url": "https://aretiq.ai/bulletins/",
  "feed_url": "https://aretiq.ai/feed/bulletins.json",
  "date": "2026-07-11",
  "generated_at": "2026-07-11T21:45:07.319833+00:00",
  "total_cves": 3,
  "groups": 1,
  "items": [
    {
      "vendor": "mervinpraison",
      "product": "praisonai",
      "cve_count": 3,
      "cve_ids": [
        "CVE-2026-61447",
        "CVE-2026-60090",
        "CVE-2026-61445"
      ],
      "cpes": [
        {
          "cpe": "cpe:2.3:a:mervinpraison:praisonai:*:*:*:*:*:*:*:*",
          "versions": "< 4.6.78"
        }
      ],
      "max_cvss": 10.0,
      "cvss_version": "4.0",
      "aas_score": 10.4,
      "severity": "HIGH",
      "summary": "PraisonAI, an open-source AI agent framework by mervinpraison, is affected by three vulnerabilities including at least one critical remote code execution flaw rated CVSS 10.0. The most severe issue involves the CodeAgent component executing LLM-generated Python code without any sandboxing, AST validation, or import restrictions, allowing attackers to achieve arbitrary code execution and full environment secret exfiltration through prompt injection. Organizations running PraisonAI prior to version 1.6.78 should upgrade immediately and review their environments for signs of compromise, particularly any unauthorized access to secrets or unexpected outbound connections. Full details are available in the vendor's GitHub security advisory.",
      "references": [
        "https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw",
        "https://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-codeagent"
      ]
    }
  ],
  "upgrades": [
    {
      "cve_id": "CVE-2026-54003",
      "vendor": "getkirby",
      "product": "kirby",
      "old_level": "theoretical",
      "new_level": "poc",
      "old_aas": 11.8,
      "new_aas": 11.53,
      "original_bulletin": "2026-07-09"
    },
    {
      "cve_id": "CVE-2026-55207",
      "vendor": "pimcore",
      "product": "pimcore",
      "old_level": "theoretical",
      "new_level": "poc",
      "old_aas": 9.14,
      "new_aas": 11.64,
      "original_bulletin": "2026-07-09"
    },
    {
      "cve_id": "CVE-2026-57480",
      "vendor": "parse-community",
      "product": "parse-server",
      "old_level": "theoretical",
      "new_level": "poc",
      "old_aas": 9.8,
      "new_aas": 12.3,
      "original_bulletin": "2026-07-08"
    }
  ]
}