


Perceptive Security
SOC/SIEM Consultancy

PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attac…
Published:
6 april 2026 om 22:00:00
Alert date:
7 april 2026 om 18:06:01
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
PraisonAI, a multi-agent teams system, contains a Zip Slip vulnerability in versions prior to 1.5.113. The vulnerability exists in the templates installation feature where the application uses Python's zipfile.extractall() without proper validation when downloading and extracting template archives from external sources like GitHub. This allows for arbitrary file write attacks as files within archives can resolve outside the intended extraction directory. The vulnerability has been patched in version 1.5.113.
Technical details
Mitigation steps:
Affected products:
PraisonAI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39307
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4ph2-f6pf-79wv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
