Impact
PraSIonAI is a multi‑agent teams system that, prior to version 4.6.59, accepts an absolute or traversing agent_file path in the POST /api/v1/runs request and forwards it to the job executor without a workspace allowlist or boundary check. This Local File Inclusion flaw (CWE‑22) lets a remote caller cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data that could facilitate further compromise.
Affected Systems
The vulnerability affects MervinPraison PraisonAI installations running any version prior to 4.6.59. Users of the public or private multi‑agent system must verify that they have not deployed these older releases.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is considered high severity. The EPSS score is <1%, indicating a very low but nonzero likelihood of exploitation. The flaw is not listed in CISA KEV, suggesting no known widespread exploitation. The likely attack vector is an unauthenticated external request to POST /api/v1/runs supplying a malicious agent_file path; no authentication or privileged access is required. The attacker can read files accessible to the service account, which may contain stored secrets or configuration, potentially enabling further post‑exploitation activity.
OpenCVE Enrichment
Github GHSA