Vulnerability Description
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite arbitrary files, enabling sensitive disclosure, denial of service, or code execution.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/MervinPraison/PraisonAI
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-766v-q9x3-g7
- https://www.vulncheck.com/advisories/praisonai-arbitrary-file-read-and-write-via
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-766v-q9x3-g7
FAQ
What is CVE-2026-56078?
CVE-2026-56078 is a vulnerability with a CVSS score of 8.8 (HIGH). PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in a...
How severe is CVE-2026-56078?
CVE-2026-56078 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56078?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.