CVE-2026-39305
CRITICALArbitrary File Write / Path Traversal in Action Orchestrator
Title source: cnaDescription
PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (../) in the target path, malicious actions can overwrite sensitive system files or drop executable payloads on the host. This vulnerability is fixed in 1.5.113.
Scores
CVSS v3
9.0
EPSS
0.0005
EPSS Percentile
15.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (3)
MervinPraison/PraisonAI
< 4.5.113
praison/praisonai
< 4.5.112
pypi/PraisonAI
0 - 4.5.113PyPI
Published
Apr 07, 2026
Tracked Since
Apr 07, 2026