CVE-2026-57119
Last modified
CVE-2026-57119 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check.
Description
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. This vulnerability is fixed in 4.6.59.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MervinPraison | PraisonAI | < 4.6.59 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-57119?
How severe is CVE-2026-57119?
How do I fix CVE-2026-57119?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57106Server-side request forgery (ssrf) in Data Quality allows an…10
- CVE-2026-57107Improper authentication in Windows Admin Center allows an au…7.8
- CVE-2026-57108Access of resource using incompatible type ('type confusion'…7.5
- CVE-2026-5711The Post Blocks & Tools plugin for WordPress is vulnerable t…6.4
- CVE-2026-57111Permissive Cross-Origin Resource Sharing (CORS) in the REST …7.5
- CVE-2026-57115PraisonAI is a multi-agent teams system. Prior to praisonaia…6.5
- CVE-2026-5712This vulnerability impacts all versions of IdentityIQ and al…8.8
- CVE-2026-57120PraisonAI is a multi-agent teams system. Prior to praisonaia…6.5
- CVE-2026-57122PraisonAI is a multi-agent teams system. Prior to 4.6.59, th…8.6
- CVE-2026-57123PraisonAI is a multi-agent teams system. Prior to praisonaia…9.8
- CVE-2026-57124PraisonAI is a multi-agent teams system. Prior to 4.6.59, th…9.8
- CVE-2026-57125PraisonAI is a multi-agent teams system. Prior to praisonai …9.8
Are you affected by CVE-2026-57119?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
