Vulnerability in PraisonAI Affects Multi-Agent Teams System Security
CVE-2026-55530

6.1MEDIUM

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55530?

PraisonAI, a system designed for multi-agent teams, contains a vulnerability in the ast_grep_rewrite function. This issue arises because the necessary @require_approval decorator is missing, allowing unauthorized agents to execute commands with --update-all. Without the proper authorization checks, these agents can rewrite files on the system, raising serious security concerns. The vulnerability has been addressed in version 1.6.58, which ensures that only authorized actions are permitted.

Affected Version(s)

PraisonAI < 4.6.58

praisonaiagents < 1.6.58

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.