<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T16:44:36.867376+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-55527</id>
    <title>CVE-2026-55527 — PraisonAI: Arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable l…</title>
    <updated>2026-10-06T16:44:36.869075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> MervinPraison PraisonAI</p>
<p>PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable locations. The fix sanitizes user_id before constructing self.user_path. This issue is fixed in version 1.6.58.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-55527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gxmw-5f7x-6g22</id>
    <title>GHSA-gxmw-5f7x-6g22 — praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversa…</title>
    <updated>2026-10-06T16:44:36.869131+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonaiagents</p>
<p>### Summary</p>
<p>`praisonaiagents/memory/file_memory.py::FileMemory.__init__()` constructs all
memory file paths by directly joining the `user_id` parameter to a base path:</p>
<p>```python
self.user_path = self.base_path / user_id      # LINE 145 — no sanitization
```</p>
<p>No validation or normalization is applied to `user_id` before the path join.
An attacker who can supply a `user_id` containing `../` sequences can write
arbitrary JSON files (memory content) to **any writable location on the filesystem**.</p>
<p>The vulnerability is confirmed **live on the current `main` branch**
(`praisonaiagents==1.6.52`) and is **distinct from GHSA-766v-q9x3-g744**
(which covered `MultiAgentMonitor` in an example file, not `FileMemory` in the
core library).</p>
<p>### Details</p>
<p>**Vulnerable code — `praisonaiagents/memory/file_memory.py` lines 139-157:**</p>
<p>```python
def __init__(
    self,
    user_id: str = "default",
    base_path: Optional[str] = None,
    ...
):
    ...
    self.user_path = self.base_path / user_id          # LINE 145 — NO SANITIZATION
    self.episodic_path = self.user_path / "episodic"</p>
<p>self.user_path.mkdir(parents=True, exist_ok=True)  # creates dirs at traversed path
    self.episodic_path.mkdir(parents=True, exist_ok=True)</p>
<p>self.config_file      = self.user_path / "config.json"
    self.short_term_file  = self.user_path / "short_term.json"
    self.long_term_file   = self.user_path / "long_term.json"
    self.entities_file    = self.user_path / "entities.json"
    self.summaries_f…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gxmw-5f7x-6g22"/>
  </entry>
</feed>
