Executive brief
PraisonAI, a system for managing multi-agent AI teams, contains a vulnerability that allows an attacker to force the AI to write files to unauthorized locations on a user's computer. By placing hidden metadata on a webpage that the AI agent crawls, an attacker can trick the agent into creating or overwriting files with malicious content. This could lead to the corruption of system files or the placement of malicious scripts on the victim's machine.
Technical details
A path traversal and arbitrary file write vulnerability exists in PraisonAI's `write_file` tool. The root cause is located in `code/tools/write_file.py`, where path validation is entirely skipped when the `workspace` variable is set to `None` (the default state in production environments). An attacker can exploit this by hosting a webpage with hidden metadata containing specific keys like `output_file` and `output_content`. When a PraisonAI agent crawls and analyzes such a page, the LLM may autonomously invoke the `write_file` tool using the attacker-provided arbitrary path. This allows for writing attacker-controlled content to any location accessible by the process. The issue is fixed in version 4.6.40 by defaulting the workspace to the current working directory and enforcing path containment checks.
Affected products
- MervinPraison (PraisonAI) PraisonAI < 4.6.40
Timeline
- 2026-05-19: patched: Fix included in security hardening batch PR #1684
- 2026-07-21: disclosed: CVE-2026-47397 published