PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace can therefore let prompt-influenced calls read and modify files outside the intended project directory, while explicitly configured workspaces remain effective. This vulnerability is fixed in 4.6.59.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 16:17
Updated : 2026-09-14 17:17
NVD link : CVE-2026-56839
Mitre link : CVE-2026-56839
CVE.ORG link : CVE-2026-56839
JSON object : View
Products Affected
No product.
