MediumVulnerabilityLLM-specific
GHSA-4xxv-6wmf-xf45: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
- Identifiers
- CVE-2026-61432GHSA-4xxv-6wmf-xf45
- Published
- Record updated
Summary
PraisonAI's FastContext feature, in praisonaiagents.context.fast, treats workspace_path as the root for code search but does not confine its model-facing tools to that directory. The execute_tool() method leaves absolute paths unchanged and turns relative traversal paths such as ../outside-secret.txt into paths outside the workspace, and the downstream grep_search, read_file and list_directory functions resolve and read them. A lower-trust prompt or caller that can influence tool arguments can therefore read, search and enumerate files outside the intended project, with the content returned to the caller or injected into the model's tool-result context.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database