Path Traversal and Resource Exhaustion Vulnerability in PraisonAI by Mervin Praison
CVE-2026-40148
6.5MEDIUM
What is CVE-2026-40148?
PraisonAI, a multi-agent teams system, has a vulnerability in its recipe registry prior to version 4.5.128. The _safe_extractall() function fails to validate the sizes of individual archive members or the cumulative extracted size before executing the extraction process. This oversight allows an attacker to exploit the system by publishing a malicious recipe bundle that consists of highly compressible data, such as a large volume of zeros. When extracted, this data can consume an excessive amount of disk space, potentially leading to a denial of service. The issue has been addressed in version 4.5.128.
Affected Version(s)
PraisonAI < 4.5.128
