Количество 2
Количество 2
CVE-2026-55540
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other code tools to access files outside the configured workspace. This issue is fixed in version 4.6.58.
GHSA-ch89-h4r2-c8f8
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55540 PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other code tools to access files outside the configured workspace. This issue is fixed in version 4.6.58. | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
GHSA-ch89-h4r2-c8f8 PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks | CVSS3: 7.1 | 0% Низкий | 22 дня назад |
Уязвимостей на страницу