CVE-2026-56078
PraisonAI
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite arbitrary files, enabling sensitive disclosure, denial of service, or code execution.
- CVSS
- 8.7
- EPSS
- 0.69% 48.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.19