GHSA-3f4v-mp44-x4x2Medium· 5.7▾ SunlitDuplicate Advisory: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-4xxv-6wmf-xf45. This link is maintained to preserve external references.
PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor canonicalizes joined paths before enforcing workspace containment. As a result, tool arguments or model-generated function calls to grep_search, glob_search, read_file, or list_directory can supply absolute paths or '../' traversal sequences to read, search, and enumerate files outside the intended workspace directory, with file contents returned to the caller or injected into the model's tool-result context.
praisonaiagents <= 1.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61432Medium· 5.7PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
CVE-2026-60089MediumPraisonAI: Project config can auto-save agent output outside the project root
GHSA-rrqj-82cc-g6h4Medium· 5.5Duplicate Advisory: PraisonAI: Project config can auto-save agent output outside the project root
CVE-2026-61443High· 8.1PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
GHSA-f352-4x87-wmjhHigh· 8.1Duplicate Advisory: PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
CVE-2026-55527High· 7.1praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …