Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

PraisonAI MCP server path traversal enables arbitrary file write and code execution

Versions of PraisonAI before 4.6.34 exposed MCP file-handling tools that joined attacker-supplied filenames onto the rules directory without containment checks, allowing directory traversal to write arbitrary files as the running user. Dropping a Python .pth file into user site-packages escalates the flaw to arbitrary code execution in later Python processes; fixed in 4.6.34.

Disclosed 8 May 2026 · Record updated 13 September 2026

Impact

Arbitrary file write outside the rules directory, escalating to arbitrary code execution in any subsequent Python process run by the affected user.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44336