{"id":"GHSA-3f4v-mp44-x4x2","title":"Duplicate Advisory: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace","summary":"Duplicate Advisory: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace","severity":"medium","cvss":5.7,"cwe":["CWE-22"],"vendor":"praisonaiagents","product":"praisonaiagents","ecosystem":"pip","affected":["praisonaiagents <= 1.6.77"],"published":"2026-07-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:48:44Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-3f4v-mp44-x4x2","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4xxv-6wmf-xf45"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61432"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0"},{"url":"https://www.vulncheck.com/advisories/praisonai-fastcontext-before-path-traversal"},{"url":"https://github.com/advisories/GHSA-3f4v-mp44-x4x2"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-08T16:52:14.777Z","slug":"GHSA-3f4v-mp44-x4x2","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-4xxv-6wmf-xf45. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor canonicalizes joined paths before enforcing workspace containment. As a result, tool arguments or model-generated function calls to grep_search, glob_search, read_file, or list_directory can supply absolute paths or '../' traversal sequences to read, search, and enumerate files outside the intended workspace directory, with file contents returned to the caller or injected into the model's tool-result context.\n\n## Affected packages\n\n- `praisonaiagents <= 1.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":31.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}