Critical severity9.1NVD Advisory· Published Sep 14, 2026· Updated Sep 15, 2026
CVE-2026-57145
CVE-2026-57145
Description
PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the process, exposing secrets and enabling persistence or application tampering. This issue is fixed in 4.6.62.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
praisonaiPyPI | < 4.6.61 | 4.6.61 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.