PT-2026-31994 · Praisonai · Praisonai
Published
2026-04-10
·
Updated
2026-04-12
·
CVE-2026-40157
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.5.128
Description
PraisonAI is a multi-agent teams system. The
cmd unpack function in the recipe CLI extracts .praison tar archives using tar.extract() without validating archive member paths. A malicious .praison bundle containing ../../ entries can write files outside the intended output directory, potentially overwriting arbitrary files on the victim's filesystem when the praisonai recipe unpack command is executed.Recommendations
Update to version 4.5.128 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai