CVE-2026-57119: PraisonAI: Unauthenticated Local File Inclusion via agent_file path in the Jobs API

Published Sep 14, 2026
·
Updated

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agentfile path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.

Affected Software

1 affected component
PraisonAI PraisonAI<4.6.59

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PraisonAI to a version that resolves this vulnerability.

    Fixed in 4.6.59

Event History

Sep 14, 2026
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

PraisonAI deployments running a version prior to 4.6.59 are exposed if the Jobs API is reachable by remote callers. The affected endpoint is POST /api/v1/runs, and no authentication is required.

2

What does an attacker need to exploit this issue?

An attacker only needs network access to the unauthenticated Jobs API. They can supply an absolute path or a path containing traversal sequences through the agent_file parameter.

3

What data could be exposed?

The server may open files that the PraisonAI service account can access. This can expose credentials, keys, environment variables, and other local data available to that account.

4

What should be done if upgrading cannot happen immediately?

Restrict remote access to the Jobs API, particularly POST /api/v1/runs, until the deployment can be updated. Limiting the service account's file permissions also reduces the local data available for disclosure.

5

How can I remediate the vulnerability?

Upgrade PraisonAI to version 4.6.59, which fixes the missing workspace allowlist and boundary check for agent_file paths.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203