Junglewise Threat Intelligence

CVE-2026-57119: PraisonAI Jobs API path traversal

CVE-2026-57119 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: praisonai (PyPI). Vendors: PyPI, PraisonAI.

Executive brief

PraisonAI is a multi-agent AI system for coordinating automated tasks. An unauthenticated attacker can exploit a path traversal vulnerability in the Jobs API to read arbitrary files on the server, potentially exposing credentials, API keys, environment variables, and other sensitive data accessible to the service account. This allows an attacker to compromise the entire system and pivot to connected infrastructure.

Technical details

The vulnerability is a path traversal (CWE-22) in the POST /api/v1/runs endpoint. The unauthenticated Jobs API accepts an absolute or traversing agent_file path parameter without validating it against a workspace allowlist or boundary check. This path is then passed unsanitized to the job executor, which opens and processes the file with the privileges of the service account. An attacker can use path traversal sequences (../) or absolute paths to read sensitive files outside the intended workspace directory. The vulnerability is fixed in version 4.6.59 through input validation hardening and access controls.

Affected products

  • PraisonAI PraisonAI before 4.6.59

Timeline

  • 2026-06-13: patched: Fix committed with hardened input validation and access controls
  • 2026-09-14: disclosed: CVE-2026-57119 published

References

Related threats