CVE-2026-56839 | MervinPraison PraisonAI up to 4.6.58 CODE_TOOLS wrappers read_file/search_replace/apply_diff workspace path traversal

SecurityVulns

A vulnerability identified as problematic has been detected in MervinPraison PraisonAI up to 4.6.58. Impacted is the function read_file/search_replace/apply_diff of the component CODE_TOOLS wrappers. This manipulation of the argument workspace causes path traversal.

This vulnerability appears as CVE-2026-56839. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More