GHSA-w37c-cq55-frjpMedium· 5.5▾ SunlitDuplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-q7m5-3jmv-vm48. This link is maintained to preserve external references.
PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute paths or parent directory traversal sequences to read arbitrary files outside the workspace and include their contents in the generated context bundle.
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61431Medium· 5.5PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
GHSA-qpq9-hwx9-cwgcHigh· 7.8Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433High· 7.8PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
GHSA-wgvq-3jxh-4qg7Medium· 5.5Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts
CVE-2026-55540High· 7.1PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks