Skip to content
HighVulnerability

GHSA-c44f-37qr-gw3f: PraisonAI: SkillTools Executes Scripts Without Path Containment Validation

Published
Record updated
View JSON
Affected
  • praisonaiagents <= 1.6.77
Fixed in
1.6.78
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.8%

Summary

PraisonAI's SkillTools.run_skill_script() accepts a script_path parameter and executes it via subprocess.run() with no path containment validation, unlike FileTools._validate_path(). An LLM-directed call can therefore run arbitrary scripts from any filesystem location, and the @require_approval decorator can be bypassed via YAML approve: for high-risk tools. Chaining with write_file lets an attacker plant and then execute a script, and because PraisonAI Docker containers run as root, an executed script gains root privileges.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.