GHSA-qjw5-xwrp-xwpq: Path Traversal
Project config can auto-save agent output outside the project root
Summary
praisonaiagents automatically reads project-local .praisonai/config.toml defaults when constructing an Agent. A repository-controlled config can set defaults.output.outputfile to an absolute path or a .. traversal path. When the developer later calls agent.start(...), PraisonAI writes the agent response to that path with open(..., "w"), creating parent directories if needed.
This lets an untrusted project overwrite files outside the project root with the privileges of the user running PraisonAI.
Technical Details
The source-to-sink path is Agent.init() project config loading to OutputConfig.outputfile to public agent.start() output auto-save. praisonaiagents/agent/agent.py applies config-driven defaults before parameter resolution; if the caller did not explicitly pass output, it calls applyconfigdefaults("output", output, OutputConfig). praisonaiagents/config/loader.py treats a config block with enabled = true as active and instantiates OutputConfig from the remaining keys. OutputConfig includes outputfile, and the agent stores that value as self.outputfile.
After agent.start(...) obtains a truthy result from self.chat(...), praisonaiagents/agent/executionmixin.py calls saveoutputtofile(str(result)) when self.outputfile is set. praisonaiagents/agent/memorymixin.py then runs expanduser() and abspath(), creates parent directories, and writes the destination with mode w. It does not constrain the resolved path to the current project, reject absolute paths, reject .., or distinguish an output path explicitly chosen by trusted application code from one loaded out of a project-local config file.
This is not a claim that explicit Agent(output=OutputConfig(outputfile=...)) chosen by trusted application code is unsafe by itself. The security boundary crossed here is the automatically consumed project-local config file: a checked-out project can steer the write destination without the application code opting into that path.
PoV
Create a project containing:
toml [defaults.output] enabled = true outputfile = "../victim-outside-project/agent-output.txt"
Then run ordinary agent code from inside that project without passing an explicit output parameter. The resolved output path escapes the project root, and PraisonAI writes the agent response there after agent.start(...).
I verified this locally without any external model call by replacing agent.chat with a deterministic offline stub after constructing the real Agent; the public start() method still performed the auto-save. Current-head output:
json { "configuredoutputfile": "../victim-outside-project/agent-output.txt", "escapedprojectroot": true, "sourcehead": "3aa9cbc2bd49c23a32be0a89a5e620d13d843eab", "startreturned": true, "canarywritten": true }
Negative controls:
json [ { "case": "safe-relative", "configuredoutputfile": "inside-output.txt", "expectedfileescapedproject": false, "expectedfileexists": true, "observedfiles": { "project/inside-output.txt": "PRAISONAINEGATIVECONTROLsafe-relative\n" }, "outsidefiles": [], "startreturned": true }, { "case": "disabled-output", "configuredoutputfile": null, "expectedfileescapedproject": null, "expectedfileexists": false, "observedfiles": {}, "outsidefiles": [], "startreturned": true } ]
The first control shows a safe relative output path stays inside the project. The second control shows a traversal outputfile is not applied when defaults.output.enabled is false.
PoC
python #!/usr/bin/env python3 import os import shutil from pathlib import Path
from praisonaiagents import Agent from praisonaiagents.config.loader import clearconfigcache
work = Path("praison-outputfile-poc").resolve() project = work / "untrusted-project" victim = work / "victim-outside-project" / "agent-output.txt"
shutil.rmtree(work, ignoreerrors=True) (project / ".praisonai").mkdir(parents=True) victim.parent.mkdir(parents=True)
(project / ".praisonai" / "config.toml").writetext( "[defaults.output]\n" "enabled = true\n" 'outputfile = "../victim-outside-project/agent-output.txt"\n', encoding="utf-8", )
os.chdir(project) clearconfigcache()
agent = Agent(instructions="offline PoC") agent.chat = lambda prompt, kwargs: "PRAISONAIOUTPUTFILECANARY\n" agent.start("offline prompt")
print(victim.readtext(encoding="utf-8")) print(victim.resolve())
Expected affected result:
- victim-outside-project/agent-output.txt is created outside untrusted-project. - The file contains PRAISONAIOUTPUTFILECANARY.
Impact
A malicious repository can cause PraisonAI to truncate and replace files outside the repository when a developer runs agent code from that directory. The write is limited to the permissions of the local user, but that commonly includes dotfiles, project-adjacent files, CI workspace files, and other user-writable paths.
The content written is the agent response rather than arbitrary bytes in the strictest sense. However, the same untrusted project can influence the agent prompt/config context, and the primitive is still an unintended file overwrite outside the project boundary.
Suggested Fix
Treat outputfile loaded from project-local config as untrusted:
- Resolve project-configured outputfile relative to the project root and reject paths that escape that root after symlink-aware normalization. - Reject absolute paths and .. traversal in project config by default. - Preserve existing behavior for explicit trusted application code, for example Agent(output=OutputConfig(outputfile=...)), or require an explicit allowexternaloutputfile opt-in for config-sourced paths. - Avoid creating parent directories outside the allowed root for config-sourced output. - Add regression tests for .praisonai/config.toml with relative traversal, absolute paths, and symlinked parent directories.
Affected Package/Versions
Confirmed affected:
- GitHub current head 3aa9cbc2bd49c23a32be0a89a5e620d13d843eab. - praisonaiagents 1.6.64, latest PyPI release at test time. - praisonaiagents 1.6.63, previous PyPI release tested.
The praisonai package version 4.6.64 depends on praisonaiagents>=1.6.64, so praisonai users can receive the affected code transitively when they use the praisonaiagents.Agent path.
Advisory History
I did not find an existing advisory summary for outputfile / OutputConfig / defaults.output project-configured output path escape in the repository advisory list.
Related but distinct advisories exist for other PraisonAI path traversal, file-write, file-read, and tool boundary issues. This report covers the praisonaiagents project config to OutputConfig.outputfile auto-save path.
No public disclosure or external submission was performed as part of this report preparation.
References
- praisonaiagents/agent/agent.py: config defaults are applied to output, then outputfile is stored on the agent. - praisonaiagents/config/loader.py: enabled config defaults instantiate the requested config class. - praisonaiagents/config/featureconfigs.py: OutputConfig.outputfile. - praisonaiagents/agent/executionmixin.py: start() auto-saves agent output. - praisonaiagents/agent/memorymixin.py: saveoutputtofile() resolves and writes the configured path without project containment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/praisonaiagentsto a version that resolves this vulnerability.Fixed in 1.6.78 - Configuration
Treat output_file values loaded from project-local .praisonai/config.toml as untrusted: resolve relative paths against the project root, apply symlink-aware normalization, reject absolute paths and .. traversal that escape the root, and do not create parent directories outside the allowed root. Require an explicit allow_external_output_file opt-in for config-sourced paths; preserve explicitly trusted application-code values such as Agent(output=OutputConfig(output_file=...)).
praisonaiagents project-configured output_file allow_external_output_file = false by default
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Developers or automation that run PraisonAI against repositories they do not fully trust are exposed, because a repository-local .praisonai/config.toml can control the output destination. Writes occur with the privileges of the user or process running PraisonAI.
What conditions are required for exploitation?
The repository-controlled configuration must enable the output block and set defaults.output.output_file to an absolute path or a path containing traversal components. The application must construct an Agent without explicitly supplying output and later call agent.start(...).
Does explicitly setting the Agent output avoid the project configuration default?
Yes. The described code applies the configured output defaults only when the caller did not explicitly pass output during Agent construction. Supplying output prevents that default-resolution path from being used.
How can teams identify potentially affected projects?
Review repository-local .praisonai/config.toml files for an enabled output configuration and a defaults.output.output_file value that is absolute or contains .. path traversal. Prioritize projects where code constructs an Agent without an output argument and invokes agent.start(...).