GHSA-rrqj-82cc-g6h4Medium· 5.5▾ SunlitDuplicate Advisory: PraisonAI: Project config can auto-save agent output outside the project root
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-qjw5-xwrp-xwpq. This link is maintained to preserve external references.
PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the developer subsequently calls agent.start() without explicitly passing an output parameter, PraisonAI writes the agent response to that path (creating parent directories as needed), allowing an untrusted checked-out project to overwrite files outside the project root with the privileges of the user running PraisonAI.
praisonaiagents <= 1.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60089MediumPraisonAI: Project config can auto-save agent output outside the project root
GHSA-3f4v-mp44-x4x2Medium· 5.7Duplicate Advisory: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
CVE-2026-61432Medium· 5.7PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
CVE-2026-61443High· 8.1PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
GHSA-f352-4x87-wmjhHigh· 8.1Duplicate Advisory: PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
CVE-2026-55527High· 7.1praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …