Path Traversal Vulnerability in PraisonAI Multi-Agent Teams System
CVE-2026-56839
7.3HIGH
What is CVE-2026-56839?
Prior to version 4.6.59, the PraisonAI multi-agent teams system had a vulnerability in its CODE_TOOLS wrappers, which did not properly enforce path containment. When the _workspace_root was kept as None, this allowed an application to expose functions such as code_read_file, code_search_replace, or code_apply_diff before properly setting a workspace. This oversight enabled users to make prompt-influenced calls that could read and modify files outside the designated project directory. Although workspaces that were explicitly configured remained effective, the lack of correct workspace management posed a significant security risk. This vulnerability was addressed and resolved in version 4.6.59.
Affected Version(s)
PraisonAI < 4.6.59
