PT-2026-57191 · Praisonai · Praisonai
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.6.78
Description
A path traversal issue exists in the ContextGatherer component. The system fails to validate include paths within
.praisoncontext and .praisoninclude files, allowing attackers to use absolute paths or parent directory traversal sequences to read arbitrary files outside the workspace and include their contents in the generated context bundle.Recommendations
Update PraisonAI to version 4.6.78 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai