Junglewise Threat Intelligence

PraisonAI path traversal in Jobs API agent_file field

Severity: high · CVSS 7.5 · Published 2026-06-18

Vendors: MervinPraison.

Executive brief

PraisonAI is an AI agent framework. A security flaw in its Jobs API allows anyone with network access to read sensitive files from the server without needing a password. This could lead to the theft of API keys, private encryption keys, and other confidential system data, potentially compromising the entire server.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the PraisonAI Jobs API due to improper path validation in the 'agent_file' field of the 'JobSubmitRequest' model. The application accepts absolute filesystem paths from unauthenticated users and passes them directly to 'yaml.safe_load(open(agent_file))' within the executor component. An attacker can exploit this by sending a crafted POST request to the '/api/v1/runs' endpoint to retrieve sensitive files such as '/etc/passwd', environment variables, or SSH keys. The vulnerability is patched in version 4.6.59.

Affected products

  • MervinPraison praisonai < 4.6.59

Timeline

  • 2026-06-17: disclosed
  • 2026-06-18: advisory: GHSA-p4pj-vh7h-6cqh published
  • 2026-06-18: patched

References