PraisonAI是Mervin Praison个人开发者的一个低代码多智能体协作框架。 PraisonAI 1.5.113之前版本存在路径遍历漏洞,该漏洞源于_validate_path函数先调用os.path.normpath折叠..序列,然后检查规范化路径中是否包含..,导致检查始终通过,可能导致简单的路径遍历到系统上的任何文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MervinPraison | PraisonAI | < 4.5.113 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39305 | 9.0 CRITICAL | Arbitrary File Write / Path Traversal in Action Orchestrator |
| CVE-2026-39307 | 8.1 HIGH | PraisonAI has an Arbitrary File Write (Zip Slip) in Templates Extraction |
| CVE-2026-39306 | 7.3 HIGH | PraisonAI recipe registry pull path traversal writes files outside the chosen output direc |
| CVE-2026-39308 | 7.1 HIGH | PraisonAI recipe registry publish path traversal allows out-of-root file write |
No comments yet