PT-2026-31994 · Praisonai · Praisonai

Published

2026-04-10

·

Updated

2026-04-12

·

CVE-2026-40157

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.5.128
Description PraisonAI is a multi-agent teams system. The cmd unpack function in the recipe CLI extracts .praison tar archives using tar.extract() without validating archive member paths. A malicious .praison bundle containing ../../ entries can write files outside the intended output directory, potentially overwriting arbitrary files on the victim's filesystem when the praisonai recipe unpack command is executed.
Recommendations Update to version 4.5.128 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40157
GHSA-99G3-W8GR-X37C

Affected Products

Praisonai