Directory Traversal Vulnerability in PraisonAI by Mervin Praison
CVE-2026-55527
7.1HIGH
What is CVE-2026-55527?
PraisonAI, a multi-agent teams system, has a vulnerability that allows attackers to exploit the FileMemory constructor by providing unsanitized user IDs, potentially leading to directory traversal. This enables the possibility of writing JSON data to arbitrary locations within the filesystem. The issue is addressed in version 1.6.58, where user ID inputs are properly sanitized to mitigate this risk.
Affected Version(s)
PraisonAI < 1.6.58
