CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-61431

CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 8, 2026·6 min read·4 visits

Executive Summary (TL;DR)

A check-after-use path traversal vulnerability in PraisonAI's ContextGatherer allows unauthorized reading of sensitive local host files.

PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.

Vulnerability Overview

PraisonAI is an open-source framework designed to orchestrate multi-agent artificial intelligence systems and streamline the assembly of codebases for LLM context windows. In versions prior to 4.6.78, the platform exposes an arbitrary local file read vulnerability via its context gathering subsystem. This component is designed to scan directories and bundle codebase files to populate large language model context windows.

The vulnerability is categorized as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / 'Path Traversal') and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). It resides in the ContextGatherer component within src/praisonai/praisonai/ui/context.py. When parsing configuration files such as .praisoncontext or .praisoninclude, the application fails to restrict paths to the designated workspace root.

An attacker can exploit this flaw by submitting malicious configuration files with absolute paths or directory traversal sequences. When the context compilation routine is triggered, these external files are parsed and appended to the context output bundle. This occurs because the safety boundaries are verified only after the files have been successfully read into memory.

Root Cause Analysis

The root cause of CVE-2026-61431 lies in a check-after-use logic flaw within the file collection routine of the ContextGatherer class. When compiling context, the class processes user-specified inclusion lists from configuration files like .praisoncontext. The application relies on Python's os.path.join() function to combine the workspace root directory with user-supplied paths.

In Python, if one of the arguments to os.path.join() is an absolute path, all previous components are discarded, and the absolute path is returned. For example, joining /app with /etc/passwd returns /etc/passwd directly. This behavior allows attackers to completely bypass the intended workspace directory structure.

The helper function add_file_content() executes an immediate read operation using open(file_path, 'r') on the resolved path. Once read, the content is immediately appended to the local context accumulation list. The boundary safety check is only executed after this append operation, via the Path(file_path).relative_to(self.directory) call.

If the path lies outside the root directory, relative_to() throws a ValueError exception. However, because this validation check is wrapped in a broad try-except block designed to catch general reading errors, the resulting exception is caught and logged as a simple warning. The execution flow continues without removing the unauthorized file content that was already appended to the context list, culminating in information disclosure.

Code Analysis

The vulnerability resides in src/praisonai/praisonai/ui/context.py before version 4.6.78. The vulnerable path resolution and inclusion logic allowed unrestricted file reads.

# Vulnerable Code Structure (Prior to v4.6.78)
def add_file_content(file_path):
    """Helper function to add file content to context."""
    try:
        # Step 1: The file is opened and read immediately
        with open(file_path, 'r', encoding='utf-8') as f:
            content = f.read()
            # Step 2: Content is appended to the context list
            context.append(
                f"File: {file_path}\n\n{content}\n\n{'=' * 50}\n"
            )
            # Step 3: Validation occurs AFTER the read and append
            # If file_path is not relative to self.directory, ValueError is raised
            self.included_files.append(
                Path(file_path).relative_to(self.directory)
            )
    except Exception as e:
        # Step 4: The ValueError is caught here, but the appended content is not removed
        logger.error(f"Error reading {file_path}: {e}")

To correct this flaw, the maintainers implemented a safe path resolution helper _resolve_include_path() in commit 393de394087e3badc79acfec490323bcc99638bd. This helper ensures that all target paths are properly sanitized and verified to reside within the designated workspace directory prior to any reading operations.

# Patched Code Structure (v4.6.78)
def _resolve_include_path(self, include_path: str) -> Optional[str]:
    """Resolve an include path and keep it within the project directory."""
    if os.path.isabs(include_path):
        candidate = os.path.expanduser(include_path)
    else:
        candidate = os.path.join(self.directory, include_path)
    
    base = os.path.realpath(self.directory)
    resolved = os.path.realpath(os.path.normpath(candidate))
    
    try:
        # Validate that the resolved path starts with the base path
        if os.path.commonpath([resolved, base]) != base:
            logger.warning("Skipping include outside project root: %s", include_path)
            return None
    except ValueError:
        logger.warning("Skipping include outside project root: %s", include_path)
        return None
    return resolved

Exploitation Methodology

Exploitation of CVE-2026-61431 relies on local or repository-level vectors where an attacker can introduce a malicious configuration file. The primary prerequisite is that the victim must execute the PraisonAI context gathering mechanism on a workspace containing these configuration files.

The attack sequence begins with the placement of a .praisoncontext or .praisoninclude file within the root of a target project directory. Within this configuration file, the attacker defines absolute paths such as /etc/passwd or relative directory traversal sequences such as ../../../../etc/shadow.

When a user runs the context generation tool using commands like praisonai context or triggers UI-based context consolidation, the application processes the configuration. It reads the files specified, appends their content, and generates a final context.txt file or feeds the context directly to an LLM provider. Although error messages will appear in the output console, the resulting file contains the fully exfiltrated contents of the requested local files.

Impact Assessment

The security impact of CVE-2026-61431 is classified as High for Confidentiality. Because the context gathering component executes with the privileges of the running PraisonAI process, any file readable by that system user can be accessed and compiled into the LLM context.

This vulnerability can lead to the disclosure of sensitive host files, including environment variables, API tokens, database credentials, ssh keys, and system files. If PraisonAI is deployed in cloud or containerized environments, exposure of container service tokens or configurations could lead to subsequent privilege escalation or infrastructure compromise.

The CVSS v3.1 vector is rated as 5.5 (Medium): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. Under CVSS v4.0, the vulnerability scores 6.8 (Medium): CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. The requirement for user interaction (loading and compiling a malicious repository) keeps the severity score moderate, though the impact of successful exploitation remains high.

Remediation and Mitigation

The primary remediation strategy for CVE-2026-61431 is upgrading the praisonai and praisonaiagents packages to version 4.6.78 or later. The update introduces robust input validation and path isolation checks that prevent arbitrary file inclusion.

# Upgrade packages using pip
pip install --upgrade praisonai praisonaiagents

For environments where an immediate upgrade is not feasible, administrators and developers must enforce strict workspace hygiene. Avoid running PraisonAI utilities within repositories or directories obtained from untrusted sources, and manually inspect .praisoncontext and .praisoninclude files for unexpected paths prior to execution.

Additionally, running the PraisonAI runtime environment inside a minimally privileged container containerized or sandbox environment is highly recommended. Restricting the container's file system access ensures that even if a path traversal occurs, the impact is isolated from the host operating system.

Fix Analysis (2)

Technical Appendix

CVSS Score
6.8/ 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Probability
0.35%
Top 73% most exploited

Affected Systems

PraisonAIPraisonAIAgents

Affected Versions Detail

Product
Affected Versions
Fixed Version
praisonai
MervinPraison
< 4.6.784.6.78
praisonaiagents
MervinPraison
< 4.6.784.6.78
AttributeDetail
CWE IDCWE-22 / CWE-200
Attack VectorLocal
CVSS Score6.8
Exploit StatusProof-of-Concept
CISA KEV StatusNo
ImpactInformation Disclosure

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located under a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Known Exploits & Detection

GitHub Security AdvisoryGHSA publication highlighting local path traversal through malicious context configurations.

Vulnerability Timeline

Vulnerability reported and advisory published
2026-02-18
Patched release v4.6.78 pushed to public registries
2026-02-18

References & Sources

  • [1]GitHub Security Advisory GHSA-q7m5-3jmv-vm48
  • [2]Fix Commit 393de394087e3badc79acfec490323bcc99638bd
  • [3]Fix Commit 1620b49f36945d8cc8ee5635b906c960df5097a0
  • [4]VulnCheck Advisory for PraisonAI Path Traversal
  • [5]CVE-2026-61431 Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•5 minutes ago•CVE-2026-107377
7.5

CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator

A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.

Amit Schendel
Amit Schendel
0 views•5 min read
•about 2 hours ago•CVE-2026-107212
7.5

CVE-2026-107212: CPU Exhaustion Denial of Service via Look-Ahead Row Parsing in Excelize

An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.

Alon Barad
Alon Barad
6 views•6 min read
•about 3 hours ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
3 views•8 min read
•about 4 hours ago•CVE-2026-106450
5.3

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

Alon Barad
Alon Barad
9 views•8 min read
•about 5 hours ago•CVE-2026-106449
3.7

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

Alon Barad
Alon Barad
6 views•6 min read
•about 6 hours ago•CVE-2026-76485
9.8

CVE-2026-76485: Remote Code Execution in Cisco NX-OS VXLAN OAM (NGOAM)

CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.

Alon Barad
Alon Barad
8 views•6 min read