Impact
PraisonAI’s multi‑agent system had a flaw in its CODE_TOOLS wrappers before version 4.6.59. The wrappers stored the workspace root as null and passed a null workspace to the read_file, search_replace, and apply_diff helper functions, which enforce path containment only when a truthy workspace is provided. As a result, exposing the code_read_file, code_search_replace, or code_apply_diff methods prior to setting a workspace enables a prompt‑influenced caller to read or modify files outside the intended project directory. This permits unauthorized file disclosure or modification, compromising confidentiality and integrity.
Affected Systems
MervinPraison’s PraisonAI application versions before 4.6.59 are affected. Users running any 4.x release prior to the 4.6.59 patch that exposes the code_read_file, code_search_replace, or code_apply_diff functionality without first setting a workspace boundary are vulnerable.
Risk and Exploitability
The CVSS base score of 7.3 indicates high severity. The EPSS score is below 1%, showing a very low predicted exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker who can interact with the exposed code tools, either locally or through a compromised user session. If the application runs with elevated privileges, the attacker could modify system files or read sensitive data. Mitigation relies on applying the vendor’s update or ensuring the workspace is set before exposing these utilities.
OpenCVE Enrichment
Github GHSA