Description
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch Immediately
AI Analysis

Impact

PraSIonAI is a multi‑agent teams system that, prior to version 4.6.59, accepts an absolute or traversing agent_file path in the POST /api/v1/runs request and forwards it to the job executor without a workspace allowlist or boundary check. This Local File Inclusion flaw (CWE‑22) lets a remote caller cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data that could facilitate further compromise.

Affected Systems

The vulnerability affects MervinPraison PraisonAI installations running any version prior to 4.6.59. Users of the public or private multi‑agent system must verify that they have not deployed these older releases.

Risk and Exploitability

With a CVSS score of 7.5 the flaw is considered high severity. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation. The flaw is not listed in CISA KEV, suggesting no known widespread exploitation. The likely attack vector is an unauthenticated external request to POST /api/v1/runs supplying a malicious agent_file path; no authentication or privileged access is required. The attacker can read files accessible to the service account, which may contain stored secrets or configuration, potentially enabling further post‑exploitation activity.

Generated by OpenCVE AI on September 21, 2026 at 00:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 4.6.59 or later.
  • Restrict the Jobs API endpoint to authenticated users or disable public access if not needed.
  • Limit network exposure of the API by applying firewall rules or reverse‑proxy authentication to prevent unauthenticated external access.

Generated by OpenCVE AI on September 21, 2026 at 00:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p4pj-vh7h-6cqh PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.
Title PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:08:17.376Z

Reserved: 2026-06-24T00:33:17.707Z

Link: CVE-2026-57119

cve-icon Vulnrichment

Updated: 2026-09-16T15:08:10.216Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:13.130

Modified: 2026-09-16T16:17:12.850

Link: CVE-2026-57119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')