Path Traversal Vulnerability in PraisonAI Action Orchestrator
CVE-2026-39305

9CRITICAL

Key Information:

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39305?

The Action Orchestrator feature in PraisonAI, prior to version 1.5.113, is susceptible to a Path Traversal vulnerability. This flaw permits unauthorized access to the file system, enabling an attacker or a compromised agent to manipulate files outside the intended workspace directory. By utilizing relative path segments (../) in their requests, an attacker can overwrite critical system files or deploy malicious payloads onto the host system. This security issue has been addressed in version 1.5.113.

Affected Version(s)

PraisonAI < 4.5.113

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.