CVE-2026-61445 affects PraisonAI versions prior to 4.6.78, exposing a critical vulnerability in the AICoder component. The flaw arises from missing path validation and command sanitization in LLM tool calls, enabling attackers to inject malicious prompts through the chat interface. This allows unauthorized users to write files to arbitrary locations on the filesystem and execute arbitrary shell commands with root privileges. The vulnerability poses a severe risk to systems utilizing the affected software, as it can lead to complete system compromise. Organizations deploying PraisonAI should immediately apply the vendor-released patch to mitigate exploitation risks. Users are advised to update to version 4.6.78 or later and review system configurations to ensure proper input validation is enforced. No evidence of active exploitation has been reported, but the high CVSS score of 9.9 underscores the urgency of remediation. This advisory aligns with standard threat intelligence practices to inform stakeholders of the potential impact and necessary mitigation steps.