File Access Vulnerability in PraisonAI Affects Multiple Versions
CVE-2026-57145

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-57145?

A file access vulnerability exists in PraisonAI, where versions prior to 4.6.62 improperly handle the LLM-controlled filepath parameter. This oversight allows malicious actors to read sensitive files and potentially modify or overwrite them, leading to data exposure and application tampering. Users are advised to upgrade to version 4.6.62 to mitigate these security risks. For more details, visit the official advisory.

Affected Version(s)

PraisonAI < 4.6.62

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.