PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute paths or parent directory traversal sequences to read arbitrary files outside the workspace and include their contents in the generated context bundle.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-10 15:16
Updated : 2026-07-10 17:41
NVD link : CVE-2026-61431
Mitre link : CVE-2026-61431
CVE.ORG link : CVE-2026-61431
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
