CVE-2026-40152Disclosure(praison / praisonaiagents)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via _validate_path(), but passes the pattern parameter directly to Path.glob() without any validation. Since Python's Path.glob() supports .. path segments, an attacker can use relative path traversal in the glob pattern to enumerate arbitrary files outside the workspace, obtaining file metadata (existence, name, size, timestamps) for any path on the filesystem. This vulnerability is fixed in 1.5.128.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonaiagents

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
praisonaiagents

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-10: 2Technical Details · 2026-04-10: 104-10
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-40152 PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via … https://www.cve.org/CVERecord?id=CVE-2026-40152

    Post summary

    The text offers a brief notation of CVE-2026-40152, describing a validation issue in a tool, but provides no PoC, exploit code, patch, or detailed technical data.

    00000130
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40152 Path Traversal in PraisonAIAgents FileTools list_files() Prior to Version 1.5.128 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40152

    Post summary

    The post discloses a path traversal vulnerability in PraisonAIAgents FileTools list_files() affecting versions prior to 1.5.128, with no mention of exploits, PoC, or mitigation.

    0000040
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonaiagents---

Explore more