CVE-2026-47397
PraisonAI has an Arbitrary File Write in Python API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path validation when `workspace=None` (always `None` in production). Version 4.6.40 fixes the issue.
| CWE | CWE-22 |
| Vendor | mervinpraison |
| Product | praisonai |
| Published | Jul 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for mervinpraison praisonai
Be the first to know when new unknown vulnerabilities affecting mervinpraison praisonai are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MervinPraison / PraisonAI
< 4.6.40