Junglewise Threat Intelligence

CVE-2026-57145: PraisonAI path traversal in multiedit tool

CVE-2026-57145 · Severity: critical · CVSS 9.1 · Published 2026-09-14

Technologies: praisonai (PyPI). Vendors: PyPI.

Executive brief

PraisonAI is a multi-agent automation system that uses LLMs to coordinate team tasks. A flaw in its file-editing tool allows AI-controlled agents to read and write arbitrary files accessible to the application process, including sensitive configuration files, credentials, and system files. An attacker can exploit this to steal secrets, establish persistence, or corrupt application functionality.

Technical details

The vulnerability is a path traversal flaw in src/praisonai/praisonai/tools/multiedit.py where LLM-controlled filepath parameters are passed directly to open() without validation, symlink resolution, workspace boundary checks, or protected-path filtering. An attacker who can influence agent prompts or directives can read arbitrary files via edit/diff operations or overwrite files with write access. No authentication bypass is required if the attacker controls the LLM input; the attack surface is the file permissions of the process user. The fix was released in version 4.6.62.

Affected products

  • Mervin Praison PraisonAI before 4.6.62

Timeline

  • 2026-09-14: disclosed
  • 2026-06-17: patched

References

Related threats