CVE-2026-39305

CRITICAL

Arbitrary File Write / Path Traversal in Action Orchestrator

Title source: cna
STIX 2.1

Description

PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (../) in the target path, malicious actions can overwrite sensitive system files or drop executable payloads on the host. This vulnerability is fixed in 1.5.113.

Scores

CVSS v3 9.0
EPSS 0.0005
EPSS Percentile 15.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (3)
MervinPraison/PraisonAI < 4.5.113
praison/praisonai < 4.5.112
pypi/PraisonAI 0 - 4.5.113PyPI
Published Apr 07, 2026
Tracked Since Apr 07, 2026