Directory Traversal Vulnerability in PraisonAI by Mervin Praison
CVE-2026-55527

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55527?

PraisonAI, a multi-agent teams system, has a vulnerability that allows attackers to exploit the FileMemory constructor by providing unsanitized user IDs, potentially leading to directory traversal. This enables the possibility of writing JSON data to arbitrary locations within the filesystem. The issue is addressed in version 1.6.58, where user ID inputs are properly sanitized to mitigate this risk.

Affected Version(s)

PraisonAI < 1.6.58

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.