Description
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace can therefore let prompt-influenced calls read and modify files outside the intended project directory, while explicitly configured workspaces remain effective. This vulnerability is fixed in 4.6.59.
Published: 2026-09-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Access
Action: Patch Now
AI Analysis

Impact

PraisonAI’s multi‑agent system had a flaw in its CODE_TOOLS wrappers before version 4.6.59. The wrappers stored the workspace root as null and passed a null workspace to the read_file, search_replace, and apply_diff helper functions, which enforce path containment only when a truthy workspace is provided. As a result, exposing the code_read_file, code_search_replace, or code_apply_diff methods prior to setting a workspace enables a prompt‑influenced caller to read or modify files outside the intended project directory. This permits unauthorized file disclosure or modification, compromising confidentiality and integrity.

Affected Systems

MervinPraison’s PraisonAI application versions before 4.6.59 are affected. Users running any 4.x release prior to the 4.6.59 patch that exposes the code_read_file, code_search_replace, or code_apply_diff functionality without first setting a workspace boundary are vulnerable.

Risk and Exploitability

The CVSS base score of 7.3 indicates high severity. The EPSS score is below 1%, showing a very low predicted exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker who can interact with the exposed code tools, either locally or through a compromised user session. If the application runs with elevated privileges, the attacker could modify system files or read sensitive data. Mitigation relies on applying the vendor’s update or ensuring the workspace is set before exposing these utilities.

Generated by OpenCVE AI on September 21, 2026 at 00:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch to update to version 4.6.59 or later.
  • Ensure a workspace boundary is set before enabling the code_read_file, code_search_replace, or code_apply_diff functionalities.
  • Restrict external access to these code agent endpoints to authenticated users or limit them to trusted internal networks.

Generated by OpenCVE AI on September 21, 2026 at 00:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gcq3-mfvh-3x25 PraisonAI Code agent tools fail open without a workspace boundary
History

Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace can therefore let prompt-influenced calls read and modify files outside the intended project directory, while explicitly configured workspaces remain effective. This vulnerability is fixed in 4.6.59.
Title PraisonAI Code agent tools fail open without a workspace boundary
Weaknesses CWE-200
CWE-22
CWE-863
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:27:09.329Z

Reserved: 2026-06-23T14:55:09.118Z

Link: CVE-2026-56839

cve-icon Vulnrichment

Updated: 2026-09-14T16:27:05.388Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:12.977

Modified: 2026-09-16T13:42:48.020

Link: CVE-2026-56839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-863

    Incorrect Authorization