Junglewise Threat Intelligence

PraisonAI path traversal in Dynamic Context history and terminal tools

Severity: high · CVSS 7.5 · Published 2026-06-18

Vendors: MervinPraison.

Executive brief

PraisonAI, an AI agent framework, contains a vulnerability in its Dynamic Context module which manages conversation history and terminal logs. An attacker can use specially crafted inputs to trick the system into reading sensitive files from the server's filesystem that are outside of the intended storage area. This could lead to the exposure of private conversation data, API keys, or system credentials stored in log files.

Technical details

A path traversal vulnerability exists in the `HistoryStore._get_history_path()` and `TerminalLogger._get_log_path()` methods of PraisonAI. The application fails to validate or sanitize the `run_id` and `agent_id` parameters before joining them with the base directory to form filesystem paths. An attacker can provide absolute paths or traversal sequences (e.g., `../`) to access any `.jsonl` or `.log` file on the host system reachable by the process. This vulnerability can be exploited remotely if the application exposes these agent tools via a network API or chat interface. The issue is addressed in version 4.6.59 by implementing path validation.

Affected products

  • MervinPraison praisonai >= 3.8.1, <= 4.6.58

Timeline

  • 2026-06-17: advisory: GitHub Advisory GHSA-22cj-m4wf-fv2c published
  • 2026-06-18: disclosed
  • 2026-06-17: patched: Fixed in version 4.6.59

References