Vulnerability in PraisonAI Multi-Agent System Allows Arbitrary File Write
CVE-2026-47397
7.1HIGH
What is CVE-2026-47397?
A vulnerability in the PraisonAI multi-agent system exposes it to potential exploitation through hidden metadata in webpages. Prior to version 4.6.40, this flaw allows agents to write content controlled by attackers to arbitrary file paths due to the improper validation of paths when the 'workspace' parameter is set to None, which is always the case in production. The latest version 4.6.40 addresses this issue, making it essential for users to update their systems immediately to mitigate risks.
Affected Version(s)
PraisonAI < 4.6.40
