PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collapses .. sequences, then checks for '..' in normalized. Since .. is already collapsed, the check always passes. This makes the check completely useless and allows trivial path traversal to any file on the system. This vulnerability is fixed in 1.5.113.
References
| Link | Resource |
|---|---|
| https://github.com/MervinPraison/PraisonAI/releases/tag/v4.5.113 | Release Notes |
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-693f-pf34-72c5 | Exploit Vendor Advisory |
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-693f-pf34-72c5 | Exploit Vendor Advisory |
Configurations
History
16 Apr 2026, 01:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/MervinPraison/PraisonAI/releases/tag/v4.5.113 - Release Notes | |
| References | () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-693f-pf34-72c5 - Exploit, Vendor Advisory | |
| First Time |
Praison
Praison praisonai |
09 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-693f-pf34-72c5 - |
07 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-07 17:16
Updated : 2026-04-16 01:34
NVD link : CVE-2026-35615
Mitre link : CVE-2026-35615
CVE.ORG link : CVE-2026-35615
JSON object : View
Products Affected
praison
- praisonai
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
