← Back to CVE search

CVE-2026-39307

PraisonAI

Description

PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a -Zip Slip- Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python-s zipfile.extractall() without verifying if the files within the archive resolve outside of the intended extraction directory. This vulnerability is fixed in 1.5.113.

CVSS 8.1EPSS 0.314%Risk 0.83
View source
Published
2026-04-07 17:16:36
Affected versions
<1.5.113
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H