VYPR
High severityGHSA Advisory· Published Jul 21, 2026· Updated Jul 23, 2026

CVE-2026-47397

CVE-2026-47397

Description

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. write_file skips path validation when workspace=None (always None in production). Version 4.6.40 fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
PraisonAIPyPI
< 4.6.404.6.40

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

1