Executive brief
PraisonAI, an AI agent framework, contains a vulnerability in its Dynamic Context Discovery feature. This feature provides tools intended to help AI agents read large data files (artifacts), but it fails to restrict these tools to the designated storage area. As a result, an attacker could use the AI agent to read sensitive files from the host server, such as passwords, secret keys, and private configuration files.
Technical details
A path traversal/arbitrary file read vulnerability exists in PraisonAI's Dynamic Context Discovery artifact tools, specifically within the `artifact_head`, `artifact_tail`, `artifact_grep`, and `artifact_chunk` functions. These tools accept a user-supplied `artifact_path` and pass it directly to the `FileSystemArtifactStore` without validating that the path resides within the configured `base_dir`. An attacker capable of influencing tool arguments via agent prompts can read any file on the host filesystem that the PraisonAI process has permissions to access. The vulnerability is rooted in the lack of path normalization and containment checks in `src/praisonai/praisonai/context/artifact_store.py`. A fix is available in version 4.6.59.
Affected products
- MervinPraison praisonai >= 3.8.1, <= 4.6.58
Timeline
- 2026-06-17: disclosed: Initial disclosure on GitHub Advisories
- 2026-06-18: advisory: Advisory published/updated
- 4.6.59: patched: Vulnerability fixed in version 4.6.59