Description
PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the process, exposing secrets and enabling persistence or application tampering. This issue is fixed in 4.6.62.
Published: 2026-09-14
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read/Write
Action: Patch Immediately
AI Analysis

Impact

PraisonAI’s multiedit tool was designed to let agents edit files by passing a filepath into the open function. In versions prior to 4.6.62 the pathname is accepted without any traversal rejection, symlink resolution, workspace boundary or protected‑path checks. This flaw is classified as CWE‑22, an improper file path validation vulnerability, which allows an attacker who can influence a prompt to read any file accessible to the PraisonAI process or to overwrite files, potentially exposing secrets, tampering with configuration, or introducing code that may execute later. The potential impact therefore spans confidentiality loss, integrity damage and persistence via file injection.

Affected Systems

All releases of PraisonAI from MervinPraison prior to v4.6.62 are vulnerable. The vulnerability was addressed in the 4.6.62 release and later versions are considered safe.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity risk, and the EPSS score of < 1% shows a very low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. The vulnerability can be leveraged whenever an attacker can dictate the prompt that drives the multiedit command; without tight control of input the attacker can supply a malicious path to read or write arbitrary files on the host machine. The absence of direct remote code execution is offset by the ability to write executable files, creating a pathway to RCE under suitable circumstances.

Generated by OpenCVE AI on September 21, 2026 at 00:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update PraisonAI to version 4.6.62 or later to apply the vendor‑supplied fix
  • If an upgrade cannot be performed immediately, disable or restrict the use of the multiedit tool within the system configuration
  • Implement strict input validation for agent‑controlled file paths, rejecting any traversal sequences or paths outside the intended workspace
  • Monitor the PraisonAI process for unexpected file writes and alert on suspicious activity

Generated by OpenCVE AI on September 21, 2026 at 00:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-29w3-p9w9-wc47 PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
History

Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the process, exposing secrets and enabling persistence or application tampering. This issue is fixed in 4.6.62.
Title PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:11:30.131Z

Reserved: 2026-06-24T01:45:48.697Z

Link: CVE-2026-57145

cve-icon Vulnrichment

Updated: 2026-09-14T17:11:02.725Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:15.017

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')