Описание
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite arbitrary files, enabling sensitive disclosure, denial of service, or code execution.
Ссылки
EPSS
Процентиль: 58%
0.00915
Низкий
8.8 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 6.5
github
5 месяцев назад
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
EPSS
Процентиль: 58%
0.00915
Низкий
8.8 High
CVSS3
Дефекты
CWE-22