PT-2026-108652 · Pypi · Praisonaiagents

Published

2026-07-15

·

Updated

2026-07-15

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-c44f-37qr-gw3f. This link is maintained to preserve external references.

Original Description

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run skill script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-F352-4X87-WMJH

Affected Products

Praisonaiagents