Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-57119

5 дней назад

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p4pj-vh7h-6cqh

3 месяца назад

PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57119

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.

CVSS3: 7.5
0%
Низкий
5 дней назад
github логотип
GHSA-p4pj-vh7h-6cqh

PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу