CVE-2026-56078 Details
Description
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite arbitrary files, enabling sensitive disclosure, denial of service, or code execution.
A path traversal vulnerability has been identified in PraisonAI versions prior to 1.5.115, specifically within the MultiAgentMonitor component. This vulnerability arises because the application fails to properly sanitize agent IDs when constructing file paths. As a result, attackers can exploit this flaw by including traversal sequences, such as '../', in agent IDs to read, write, or overwrite arbitrary files. This exploitation could lead to unauthorized disclosure of sensitive information, denial-of-service conditions, or even arbitrary code execution.
Users can update to PraisonAI version 1.5.115 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 18, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-766v-q9x3-g744 | CISA-ADP | AdvisoryBundleExploitRemedyTechnical AnalysisVendor |
| https://github.com/MervinPraison/PraisonAI | [email protected] | ProductSource CodeVendor |
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-766v-q9x3-g744 | [email protected] | AdvisoryBundleExploitRemedyTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/praisonai-arbitrary-file-read-and-write-via-path-traversal-in-multiagentmonitor | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MervinPraison PraisonAI | < 1.5.115 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |
Volerion