Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f352-4x87-wmjh

Опубликовано: 15 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

EPSS

Процентиль: 40%
0.00499
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 месяца назад

PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containment validation. Attackers can supply absolute file paths to execute arbitrary scripts from any filesystem location, including those outside the intended working directory.

EPSS

Процентиль: 40%
0.00499
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-22