GHSA-wgvq-3jxh-4qg7Medium· 5.5▾ SunlitDuplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-xpx6-x8c2-mw5w. This link is maintained to preserve external references.
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60088Medium· 5.5PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace
GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
GHSA-w37c-cq55-frjpMedium· 5.5Duplicate Advisory: PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
CVE-2026-61431Medium· 5.5PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
GHSA-q65p-7p84-495cCritical· 9.8Duplicate Advisory: PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL
CVE-2026-55540High· 7.1PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks