PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, ispathwithindirectory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing readfile and other code tools to access files outside the configured workspace. This issue is fixed in version 4.6.58.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55540.json",
"cwe_ids": [
"CWE-22"
],
"cna_assigner": "GitHub_M"
}