Executive brief
PraisonAI is an AI agent framework. A security flaw in its Jobs API allows anyone with network access to read sensitive files from the server without needing a password. This could lead to the theft of API keys, private encryption keys, and other confidential system data, potentially compromising the entire server.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the PraisonAI Jobs API due to improper path validation in the 'agent_file' field of the 'JobSubmitRequest' model. The application accepts absolute filesystem paths from unauthenticated users and passes them directly to 'yaml.safe_load(open(agent_file))' within the executor component. An attacker can exploit this by sending a crafted POST request to the '/api/v1/runs' endpoint to retrieve sensitive files such as '/etc/passwd', environment variables, or SSH keys. The vulnerability is patched in version 4.6.59.
Affected products
- MervinPraison praisonai < 4.6.59
Timeline
- 2026-06-17: disclosed
- 2026-06-18: advisory: GHSA-p4pj-vh7h-6cqh published
- 2026-06-18: patched