---
id: GHSA-rrqj-82cc-g6h4
title: >-
  Duplicate Advisory: PraisonAI: Project config can auto-save agent output
  outside the project root
summary: >-
  Duplicate Advisory: PraisonAI: Project config can auto-save agent output
  outside the project root
severity: medium
cvss: 5.5
cwe:
  - CWE-22
vendor: praisonaiagents
product: praisonaiagents
ecosystem: pip
affected:
  - praisonaiagents <= 1.6.77
published: '2026-07-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:36:29Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-rrqj-82cc-g6h4'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qjw5-xwrp-xwpq
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-60089'
  - url: >-
      https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-config-toml
  - url: 'https://github.com/advisories/GHSA-rrqj-82cc-g6h4'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-08T16:52:14.782Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-qjw5-xwrp-xwpq. This link is maintained to preserve external references.

### Original Description
PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the developer subsequently calls agent.start() without explicitly passing an output parameter, PraisonAI writes the agent response to that path (creating parent directories as needed), allowing an untrusted checked-out project to overwrite files outside the project root with the privileges of the user running PraisonAI.

## Affected packages

- `praisonaiagents <= 1.6.77`

## Remediation

Refer to the advisory for the patched release.
