{"id":"CVE-2026-57145","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-57145","generatedAt":"2026-09-20T15:03:30.343Z","title":"Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks.","description":"PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the process, exposing secrets and enabling persistence or application tampering. This issue is fixed in 4.6.62.","published":"2026-09-14T16:17:15.000Z","lastModified":"2026-09-15T14:45:29.000Z","status":"Deferred","sourceIdentifier":"security-advisories@github.com","cvss":{"version":"3.1","score":9.1,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"},"cwe":["CWE-22"],"affected":[],"epss":{"score":0.00361,"percentile":0.2986,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"high","text":"High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit."},"changes":[],"references":[{"url":"https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33","source":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.62","source":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-29w3-p9w9-wc47","source":"security-advisories@github.com"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-57145","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}