{"id":"GHSA-rrqj-82cc-g6h4","title":"Duplicate Advisory: PraisonAI: Project config can auto-save agent output outside the project root","summary":"Duplicate Advisory: PraisonAI: Project config can auto-save agent output outside the project root","severity":"medium","cvss":5.5,"cwe":["CWE-22"],"vendor":"praisonaiagents","product":"praisonaiagents","ecosystem":"pip","affected":["praisonaiagents <= 1.6.77"],"published":"2026-07-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:36:29Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-rrqj-82cc-g6h4","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qjw5-xwrp-xwpq"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60089"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-config-toml"},{"url":"https://github.com/advisories/GHSA-rrqj-82cc-g6h4"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-08T16:52:14.782Z","slug":"GHSA-rrqj-82cc-g6h4","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-qjw5-xwrp-xwpq. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the developer subsequently calls agent.start() without explicitly passing an output parameter, PraisonAI writes the agent response to that path (creating parent directories as needed), allowing an untrusted checked-out project to overwrite files outside the project root with the privileges of the user running PraisonAI.\n\n## Affected packages\n\n- `praisonaiagents <= 1.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}