PT-2026-39007 · Praisonai · Praisonai

·

CVE-2026-44340

·

Published

2026-05-08

·

Updated

2026-07-13

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.6.37
Description The safe extractall() helper function, used in recipe pull, recipe publish, and recipe unpack flows, fails to validate member.linkname and does not reject symlink or hardlink members. Additionally, it calls tar.extractall(dest dir) without the filter="data" option. An attacker can use a bundle containing a symlink that points outside the destination directory, followed by a regular file that traverses this symlink, to write arbitrary content to a chosen location on the victim's filesystem.
Recommendations Update to version 4.6.37.

Exploit

Fix

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44340
GHSA-9Q28-GHCR-C4X3
PYSEC-2026-2909

Affected Products

Praisonai