{"id":"CVE-2026-56839","aliases":["GHSA-gcq3-mfvh-3x25","PYSEC-2026-3512"],"url":"https://o3.security/vulnerability/CVE-2026-56839","summary":"PraisonAI Code agent tools fail open without a workspace boundary","details":"PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace can therefore let prompt-influenced calls read and modify files outside the intended project directory, while explicitly configured workspaces remain effective. This vulnerability is fixed in 4.6.59.","published":"2026-09-14T15:00:45.357Z","modified":"2026-09-16T03:47:07.772644420Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N"},"epss":{"score":0.00304,"percentile":0.23173,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"praisonai","fixedVersion":"4.6.59"}],"fix":{"url":"https://github.com/MervinPraison/PraisonAI/commit/b4270173d4123fb1ee8910588f0896668ee21b59","label":"MervinPraison/PraisonAI@b427017"},"references":[{"type":"WEB","url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.59"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56839.json"},{"type":"ADVISORY","url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gcq3-mfvh-3x25"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56839"},{"type":"FIX","url":"https://github.com/MervinPraison/PraisonAI/commit/b4270173d4123fb1ee8910588f0896668ee21b59"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:47:07.772644420Z"}}