CVE-2026-61431: CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer
CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer Vulnerability ID: CVE-2026-61431 CVSS Score: 6.8 Published: 2026-10-08 PraisonAI is vulnerable to an arbitrary local file rea
CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer
Vulnerability ID: CVE-2026-61431
CVSS Score: 6.8
Published: 2026-10-08
PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.
TL;DR
A check-after-use path traversal vulnerability in PraisonAI's ContextGatherer allows unauthorized reading of sensitive local host files.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22 / CWE-200
- Attack Vector: Local
- CVSS Score: 6.8
- Exploit Status: Proof-of-Concept
- CISA KEV Status: No
- Impact: Information Disclosure
Affected Systems
- PraisonAI
- PraisonAIAgents
-
praisonai: < 4.6.78 (Fixed in:
4.6.78) -
praisonaiagents: < 4.6.78 (Fixed in:
4.6.78)
Code Analysis
Commit: 393de39
Fix path safety and validate include paths using _resolve_include_path before reading files
Commit: 1620b49
Fix Formula/Orphan Cleanup and additional path safety configurations
Exploit Details
- GitHub Security Advisory: GHSA publication highlighting local path traversal through malicious context configurations.
Mitigation Strategies
- Upgrade PraisonAI to version 4.6.78 or later to resolve the logic bug.
- Manually audit .praisoncontext and .praisoninclude files within codebase workspaces before execution.
- Containerize PraisonAI execution within restricted, non-root system environments.
Remediation Steps:
- Execute 'pip install --upgrade praisonai praisonaiagents' to pull down the safe version.
- Verify that the active version of PraisonAI is 4.6.78 or above.
- Implement secure repository validation to filter untrusted user configurations in automated pipelines.
References
- GitHub Security Advisory GHSA-q7m5-3jmv-vm48
- Fix Commit 393de394087e3badc79acfec490323bcc99638bd
- Fix Commit 1620b49f36945d8cc8ee5635b906c960df5097a0
- VulnCheck Advisory for PraisonAI Path Traversal
- CVE-2026-61431 Record
Read the full report for CVE-2026-61431 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.