Disclosure summary
### Summary `SkillTools.run_skill_script()` accepts a `script_path` parameter and executes it via `subprocess.run()` without any path containment validation. While `FileTools` has `_validate_path()` with traversal detection, `SkillTools` performs none. An LLM-directed call can execute arbitrary scripts from any filesystem location. The `@require_approval` decorator can be bypassed via YAML `approve:` for high-risk tools. ### Details `src/praisonai-agents/praisonaiagents/tools/skill_tools.py` (lines 69-119): ```python def run_skill_script(self, script_path: str, ...): script_path = os.path.expanduser(script_path) if not os.path.isabs(script_path): script_path = os.path.join(self._working_directory, script_path) script_path = os.path.abspath(script_path) if not os.path.exists(script_path): return f"Error: Script not found at {script_path}" # No path traversal check, no containment validation # Directly executes whatever is at that path: result = subprocess.run(cmd, ...) ``` By contrast, `FileTools._validate_path()` (`src/praisonai-agents/praisonaiagents/tools/file_tools.py`, lines 42-78) properly validates that the resolved path stays within the working directory: ```python def _vali
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-c44f-37qr-gw3f
Open original source · Updated Oct 08, 2026
PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | praisonaiagents | 1.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-08T12:49:23-04:00
MODIFIED 2026-10-08T12:49:24-04:00
INGESTED 2026-10-10T20:25:13-04:00