{"id":"GHSA-wgvq-3jxh-4qg7","title":"Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts","summary":"Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts","severity":"medium","cvss":5.5,"cwe":["CWE-22"],"vendor":"praisonai","product":"praisonai","ecosystem":"pip","affected":["praisonai <= 4.6.77"],"published":"2026-07-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T17:57:43Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-wgvq-3jxh-4qg7","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xpx6-x8c2-mw5w"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60088"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-custom-commands"},{"url":"https://github.com/advisories/GHSA-wgvq-3jxh-4qg7"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-08T18:58:11.318Z","slug":"GHSA-wgvq-3jxh-4qg7","body":"## Overview\n\n### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-xpx6-x8c2-mw5w. This link is maintained to preserve external references.\n\n### Original Description\nPraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.\n\n## Affected packages\n\n- `praisonai <= 4.6.77`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}