CyberRota Analysis
AI-GeneratedPraisonAI versions prior to 4.6.78 are vulnerable due to inadequate validation of file path references in custom command templates, enabling attackers to exploit path traversal vulnerabilities. This flaw allows unauthorized file access, potentially leading to the exfiltration of sensitive information from the system. Organizations using PraisonAI should prioritize patching to mitigate the risk of data leakage and unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.