PT-2026-31787 · Praisonai · Praisonai
Published
2026-04-09
·
Updated
2026-04-10
·
CVE-2026-40148
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.5.128
Description
PraisonAI is a multi-agent teams system. The
safe extractall() function in the recipe registry validates archive members against path traversal attacks but does not check individual member sizes, cumulative extracted size, or member count before calling tar.extractall(). An attacker can publish a malicious recipe bundle containing highly compressible data that exhausts the victim's disk when pulled via LocalRegistry.pull() or HttpRegistry.pull().Recommendations
Update to version 4.5.128 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai