{"id":"CVE-2026-56839","title":"PraisonAI is a multi-agent teams system","summary":"PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy w…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-22","CWE-200","CWE-863"],"vendor":"MervinPraison","product":"PraisonAI","affected":["PraisonAI < 4.6.59"],"patched":["praisonai 4.6.59"],"published":"2026-09-14","updated":"2026-09-16","sourceUpdated":"2026-09-16T13:42:48.020","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56839","references":[{"url":"https://github.com/MervinPraison/PraisonAI/commit/b4270173d4123fb1ee8910588f0896668ee21b59","label":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.59","label":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gcq3-mfvh-3x25","label":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gcq3-mfvh-3x25","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/MervinPraison/PraisonAI"}],"tags":["nvd","cve.org","exploit-available","osv","pip"],"epss":0.00304,"epssPercentile":0.23331,"aliases":["GHSA-gcq3-mfvh-3x25"],"ecosystem":"pip","exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-14T16:26:45.502398Z"},"ingestedAt":"2026-07-21T19:04:57.159Z","slug":"CVE-2026-56839","body":"## Overview\n\nPraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace can therefore let prompt-influenced calls read and modify files outside the intended project directory, while explicitly configured workspaces remain effective. This vulnerability is fixed in 4.6.59.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-56839)\n\nAffected packages:\n\n- `praisonai < 4.6.59`\n\nPatched in:\n\n- `praisonai 4.6.59`\n\nSource: https://osv.dev/vulnerability/GHSA-gcq3-mfvh-3x25","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":203081,"id":"CVE-2026-56839","ts":1789409572446,"field":"exploit_available","old":"false","new":"true"}]}