---
id: GHSA-3f4v-mp44-x4x2
title: >-
  Duplicate Advisory: PraisonAI: FastContext path resolution permits absolute
  and traversal reads outside the workspace
summary: >-
  Duplicate Advisory: PraisonAI: FastContext path resolution permits absolute
  and traversal reads outside the workspace
severity: medium
cvss: 5.7
cwe:
  - CWE-22
vendor: praisonaiagents
product: praisonaiagents
ecosystem: pip
affected:
  - praisonaiagents <= 1.6.77
published: '2026-07-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:48:44Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-3f4v-mp44-x4x2'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4xxv-6wmf-xf45
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61432'
  - url: >-
      https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-fastcontext-before-path-traversal
  - url: 'https://github.com/advisories/GHSA-3f4v-mp44-x4x2'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-08T16:52:14.777Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4xxv-6wmf-xf45. This link is maintained to preserve external references.

### Original Description
PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor canonicalizes joined paths before enforcing workspace containment. As a result, tool arguments or model-generated function calls to grep_search, glob_search, read_file, or list_directory can supply absolute paths or '../' traversal sequences to read, search, and enumerate files outside the intended workspace directory, with file contents returned to the caller or injected into the model's tool-result context.

## Affected packages

- `praisonaiagents <= 1.6.77`

## Remediation

Refer to the advisory for the patched release.
