CVE-2026-39305: Arbitrary File Write / Path Traversal in Action Orchestrator
PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (../) in the target path, malicious actions can overwrite sensitive system files or drop executable payloads on the host. This vulnerability is fixed in 1.5.113.
Other sources
The Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (../) in the target path, malicious actions can overwrite sensitive system files or drop executable payloads on the host.
Details Location: src/praisonai/praisonai/cli/features/actionorchestrator.py (Lines 402, 409, 423)
Vulnerable Code snippet: python target = workspace / step.target
In the applystep method, paths are constructed by concatenating the workspace path with a user-supplied step.target string: target = workspace / step.target. The code fails to resolve and validate that the final absolute path remains within the bounds of the workspace directory. When processing FILECREATE or FILEEDIT actions, this flaw permits arbitrary file modification.
PoC Construct a malicious ActionStep payload with path traversal characters:
python from praisonai.cli.features.actionorchestrator import ActionStep, ActionType, ActionStatus
Payload targeting a file outside the workspace step = ActionStep( id="testtraversal", actiontype=ActionType.FILECREATE, description="Malicious file write", target="../../../../../../../tmp/orchestratorpwned.txt", params={"content": "pwned"}, status=ActionStatus.APPROVED )
When the orchestrator applies this step, it writes to the traversed path applystep(step)
Impact This is an Arbitrary File Write vulnerability. Anyone running the Action Orchestrator to apply modifications is vulnerable. A malicious prompt could trick the agent into generating a plan that overwrites critical files (e.g., ~/.ssh/authorizedkeys, .bashrc) leading to Remote Code Execution (RCE) or system corruption.
— GitHub