PT-2026-57432 · Praisonai · Praisonai
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 4.6.78
Description
The software fails to validate file path references within custom command templates. This allows attackers to read files outside the designated workspace by using absolute paths or path traversal sequences, such as
@../outside secret.txt, in project command files. This flaw enables the exfiltration of files readable by the process into model prompts.Recommendations
Update PraisonAI to version 4.6.78 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai