← Zurück zur CVE-Suche

CVE-2026-39307

PraisonAI

Beschreibung

PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a -Zip Slip- Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python-s zipfile.extractall() without verifying if the files within the archive resolve outside of the intended extraction directory. This vulnerability is fixed in 1.5.113.

CVSS 8.1EPSS 0.314%Risiko 0.83
Quelle öffnen
Veröffentlicht
2026-04-07 17:16:36
Betroffene Versionen
<1.5.113
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H