CRITICAL🇵🇱 Wersja polska

CVE-2026-40157

CVSS 9.4v4.0pub. 2026-04-10upd. 2026-04-24

PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without validating archive member paths. A .praison bundle containing ../../ entries will write files outside the intended output directory. An attacker who distributes a malicious bundle can overwrite arbitrary files on the victim's filesystem when they run praisonai recipe unpack. This vulnerability is fixed in 4.5.128.

🤖 AI Analysis
How it works

The cmd_unpack function in the CLI interface (praisonai recipe unpack command) extracts .praison archives using tar.extract() without validating the paths contained in the archive. An attacker can prepare a malicious .praison package containing entries with paths like ../../, which during extraction point to directories outside the target output directory. When the victim runs the unpack command on such a package, files are written outside the intended directory — potentially anywhere on the file system.

Impact

An attacker can overwrite arbitrary files on the victim's file system, which may lead to system takeover, integrity compromise, or service disruption (e.g., by overwriting configuration files, system binaries, or startup scripts).

Mitigation & patch

Update PraisonAI to version 4.5.128 or later, in which the vulnerability has been removed. Until the update is applied, avoid unpacking .praison packages from untrusted sources.

Who is affected

PraisonAI (Praisonai) in versions before 4.5.128.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Praison Praisonai

    APP
    Praison
    < 4.5.128
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-44336CRITICAL9.4PL ✓same product

Path Traversal i RCE w PraisonAI MCP Server (serwer narzędzi plikowych)

CVE-2026-41497CRITICAL9.8PL ✓same product

Command Injection w PraisonAI — brak walidacji poleceń MCP

CVE-2026-40289CRITICAL9.1PL ✓same product

PraisonAI – nieuwierzytelnione przejęcie sesji przeglądarki przez WebSocket

CVE-2026-40313CRITICAL9.1PL ✓same product

PraisonAI – wyciek tokenów GitHub przez atak ArtiPACKED w CI/CD

CVE-2026-40288CRITICAL9.8PL ✓same product

PraisonAI — RCE i command injection przez niezaufowane pliki YAML