Описание
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.
Ссылки
EPSS
Процентиль: 4%
0.00147
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 5.5
github
около 1 месяца назад
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.
EPSS
Процентиль: 4%
0.00147
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-22