Impact
PraisonAI’s multiedit tool was designed to let agents edit files by passing a filepath into the open function. In versions prior to 4.6.62 the pathname is accepted without any traversal rejection, symlink resolution, workspace boundary or protected‑path checks. This flaw is classified as CWE‑22, an improper file path validation vulnerability, which allows an attacker who can influence a prompt to read any file accessible to the PraisonAI process or to overwrite files, potentially exposing secrets, tampering with configuration, or introducing code that may execute later. The potential impact therefore spans confidentiality loss, integrity damage and persistence via file injection.
Affected Systems
All releases of PraisonAI from MervinPraison prior to v4.6.62 are vulnerable. The vulnerability was addressed in the 4.6.62 release and later versions are considered safe.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity risk, and the EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. The vulnerability can be leveraged whenever an attacker can dictate the prompt that drives the multiedit command; without tight control of input the attacker can supply a malicious path to read or write arbitrary files on the host machine. The absence of direct remote code execution is offset by the ability to write executable files, creating a pathway to RCE under suitable circumstances.
OpenCVE Enrichment
Github GHSA