Vulnerability in PraisonAI Affects Multi-Agent Teams System Security
CVE-2026-55530
6.1MEDIUM
What is CVE-2026-55530?
PraisonAI, a system designed for multi-agent teams, contains a vulnerability in the ast_grep_rewrite function. This issue arises because the necessary @require_approval decorator is missing, allowing unauthorized agents to execute commands with --update-all. Without the proper authorization checks, these agents can rewrite files on the system, raising serious security concerns. The vulnerability has been addressed in version 1.6.58, which ensures that only authorized actions are permitted.
Affected Version(s)
PraisonAI < 4.6.58
praisonaiagents < 1.6.58
