CVE-2026-57145Critical· 9.1▾ MidnightPraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the process, exposing secrets and enabling persistence or application tampering. This issue is fixed in 4.6.62.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonai < 4.6.61Patched in:
praisonai 4.6.61Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57132High· 8.2PraisonAI is a multi-agent teams system
CVE-2026-57119High· 7.5PraisonAI is a multi-agent teams system
CVE-2026-56839High· 7.3PraisonAI is a multi-agent teams system
CVE-2026-55540High· 7.1PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
CVE-2026-57122High· 8.6PraisonAI is a multi-agent teams system
CVE-2026-57126High· 8.5PraisonAI is a multi-agent teams system