Executive brief
PraisonAI, an AI agent framework, contains a vulnerability in how it handles custom command templates. If a user runs a command from a malicious project repository, the software can be tricked into reading sensitive files from the user's computer (such as configuration files or SSH keys) and sending them to the AI model provider. This could lead to the unauthorized exposure of private data to third-party AI services.
Technical details
A path traversal vulnerability exists in PraisonAI's custom command feature within `src/praisonai/praisonai/cli/features/custom_definitions.py`. The `TemplateInterpolator._interpolate_files()` method processes `@path` references by joining them with the current working directory without performing canonicalization or containment checks. An attacker can craft a malicious `.praisonai/commands/*.md` file in a repository that uses `../` sequences or absolute paths to reference files outside the project root. When a user executes `praisonai run --command <name>`, the application reads the targeted files and includes their contents in the prompt sent to the LLM. This issue was addressed in version 4.6.78.
Affected products
- MervinPraison PraisonAI < 4.6.78
Timeline
- 2026-06-25: advisory: GitHub Security Advisory published
- 2026-07-11: disclosed: NVD publication date