External risk intelligence

PraisonAI Path Traversal Vulnerability Exposes Secrets and Enables Tampering.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-57145

PraisonAI is a multi-agent framework used for building and managing AI agents. While it may be utilized in internal development or local automation tasks, it can also be deployed as a backend service or API that interacts with web-based interfaces or external agents, making internet reachability possible depending on how the system is integrated and deployed by the user.

Path Traversal

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in the PraisonAI multi-agent system that could allow unauthorized access to sensitive files or modification of application behavior. The flaw stems from how file paths are handled, potentially enabling prompt-influenced agents to read or overwrite files, which could expose secrets or compromise the application's integrity.

  • Agents can read or overwrite files.
  • Critical flaw in how AI agents handle file paths.
  • Confirm relevance and exposure of the AI system.

Attack Path

How an attacker could exploit the issue

An attacker could leverage an unprotected file path parameter to read or write files on a system running PraisonAI. This occurs because the system does not properly validate file paths before opening them, allowing for potential directory traversal. Prompt-influenced agents can exploit this to access sensitive information or alter application behavior.

  • Unauthenticated network access
  • Path parameter manipulation
  • Sensitive data exposure and tampering

Live Threat

Current exploitation, exposure, and threat context

When PraisonAI is deployed with web-accessible interfaces or external agent interactions, prompt-influenced agents could read or overwrite files accessible to the process. This could expose secrets or allow application tampering, depending on the process's permissions.

  • System files could be read or overwritten.
  • Agents can access files via edit and diff behavior.
  • Sensitive information exposure or application tampering.

Operational Fix

Recommended remediation, mitigation, and detection steps

The PraisonAI multi-agent system, specifically versions prior to 4.6.62, contains a critical vulnerability allowing prompt-influenced agents to read or overwrite files. This impacts system integrity and confidentiality. Owners of PraisonAI deployments should first identify all instances, assess their network exposure and business criticality, and then coordinate with the platform or application teams to plan remediation based on risk.

  • Platform and application teams own remediation.
  • Verify PraisonAI instances and exposure.
  • Plan and execute upgrades or mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI and how is it used?

PraisonAI is a framework designed to build and manage multi-agent teams. It enables developers to orchestrate multiple AI agents to work together on complex tasks, often automating workflows that require reading, writing, or editing files. It is commonly utilized in automation pipelines and can serve as a backend service for AI-powered applications.

What is the vulnerability in CVE-2026-57145?

This CVE involves a Path Traversal weakness, classified as CWE-22. It occurs because the software fails to properly sanitize or validate file path inputs before opening them. As a result, the system may inadvertently treat malicious or unexpected paths as legitimate, allowing file operations to occur outside of intended, safe directories.

How does an attacker trigger this path traversal?

The flaw is triggered when an AI agent, influenced by a specific prompt, provides a path parameter that directs the system to sensitive areas of the file system. It is important to note that standard, safe file operations within a restricted workspace do not trigger this vulnerability; the issue specifically arises when the software lacks boundary checks, allowing the process to follow arbitrary paths or symlinks.

Is my PraisonAI deployment at risk?

Risk depends on your specific integration. According to Halo Surface Signal, because PraisonAI can be deployed as an internet-facing backend service or API, it may be accessible to external actors. If your instance is reachable from the internet or interacts with untrusted external agents, it has a higher potential for exposure compared to isolated, internal-only development environments.

How do I secure my environment against this?

The primary response is to update PraisonAI to version 4.6.62 or later, which includes the necessary path validation fixes. Before updating, perform an inventory to locate all active instances in your environment, determine if they are network-accessible, and coordinate with your development teams to apply the patch and verify that the file-handling logic is now restricted to authorized workspace boundaries.

References