Description
PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a -Zip Slip- Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python-s zipfile.extractall() without verifying if the files within the archive resolve outside of the intended extraction directory. This vulnerability is fixed in 1.5.113.
CVSS 8.1EPSS 0.314%Risk 0.83
View source- Published
- 2026-04-07 17:16:36
- Affected versions
- <1.5.113
- Type
- Core software
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H