Medium severity6.2NVD Advisory· Published Apr 9, 2026· Updated Apr 17, 2026
CVE-2026-40117
CVE-2026-40117
Description
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path parameter. Unlike file_tools.read_file which enforces workspace boundary confinement, and unlike run_skill_script which requires critical-level approval, read_skill_file has neither protection. An agent influenced by prompt injection can exfiltrate sensitive files without triggering any approval prompt. This vulnerability is fixed in 1.5.128.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
praisonaiagentsPyPI | < 1.5.128 | 1.5.128 |
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/MervinPraison/PraisonAI/security/advisories/GHSA-grrg-5cg9-58pfnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-grrg-5cg9-58pfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-40117ghsaADVISORY
News mentions
0No linked articles in our index yet.