Disclosure summary
# FastContext path resolution permits absolute and traversal reads outside the workspace ## Summary PraisonAI's `praisonaiagents.context.fast` FastContext feature treats `workspace_path` as the root directory for code search, but its model-facing search tools and high-level `read_context()` helper accept absolute paths and `..` traversal paths without checking that the resolved path remains under that workspace. A lower-trust prompt or caller that can influence FastContext tool arguments can read, search, and enumerate files outside the intended project workspace; the resulting file content is then returned to the caller or injected into the model's tool-result context. ## Technical Details `FastContextAgent` documents `workspace_path` as the "Root directory for searches" and stores it as an absolute path: ```python class FastContextAgent: """Specialized agent for fast parallel code search. Attributes: workspace_path: Root directory for searches """ def __init__(self, workspace_path: str, ...): self.workspace_path = os.path.abspath(workspace_path) ``` The same class exposes `grep_search`, `glob_search`, `read_file`, and `list_directory` as model function-call tools via `get_tools()
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-4xxv-6wmf-xf45
Open original source · Updated Oct 08, 2026
PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | praisonaiagents | 1.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-08T12:48:52-04:00
MODIFIED 2026-10-08T12:48:53-04:00
INGESTED 2026-10-10T20:25:13-04:00