GHSA-f352-4x87-wmjhHigh· 8.1▾ TwilightDuplicate Advisory: PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-c44f-37qr-gw3f. This link is maintained to preserve external references.
PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.
praisonaiagents <= 1.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61443High· 8.1PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
CVE-2026-60089MediumPraisonAI: Project config can auto-save agent output outside the project root
GHSA-rrqj-82cc-g6h4Medium· 5.5Duplicate Advisory: PraisonAI: Project config can auto-save agent output outside the project root
GHSA-3f4v-mp44-x4x2Medium· 5.7Duplicate Advisory: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
CVE-2026-61432Medium· 5.7PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
CVE-2026-55527High· 7.1praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …