Disclosure summary
# ContextGatherer include resolution permits absolute and traversal reads outside the workspace ## Summary PraisonAI's `praisonai.ui.context.ContextGatherer` treats the configured `directory` as the project workspace, but project-controlled `.praisoncontext` and `.praisoninclude` files can name absolute paths or `..` traversal paths. When context gathering runs, PraisonAI opens those outside paths and appends their contents to the generated context bundle. An attacker who can supply or modify a workspace repository can therefore cause process-readable files outside the intended project root to be sent to the caller or model as project context. ## Technical Details `ContextGatherer.get_include_paths()` reads include entries directly from `.praisoncontext` and `.praisoninclude` under the configured workspace. It stores each non-comment line as a raw include path: ```python include_file = os.path.join(self.directory, '.praisoncontext') if os.path.exists(include_file): with open(include_file, 'r') as f: include_paths.extend( line.strip() for line in f if line.strip() and not line.startswith('#') ) ``` When `.praisoncontext` is present, `gather_context()` passes every include entry thro
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-q7m5-3jmv-vm48
Open original source · Updated Oct 08, 2026
PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | praisonai | 4.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-08T13:58:30-04:00
MODIFIED 2026-10-08T13:58:30-04:00
INGESTED 2026-10-10T20:25:13-04:00