CVE-2026-56839High· 7.3▾ MidnightPoC availablePraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy w…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
0.3%
Last analysed / modified upstream
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace can therefore let prompt-influenced calls read and modify files outside the intended project directory, while explicitly configured workspaces remain effective. This vulnerability is fixed in 4.6.59.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonai < 4.6.59Patched in:
praisonai 4.6.59Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57119High· 7.5PraisonAI is a multi-agent teams system
CVE-2026-57125Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57129High· 7.5PraisonAI is a multi-agent teams system
CVE-2026-57115Medium· 6.5PraisonAI is a multi-agent teams system
GHSA-gcq3-mfvh-3x25High· 7.3PraisonAI Code agent tools fail open without a workspace boundary
CVE-2026-57112High· 8.3PraisonAI is a multi-agent teams system