CVE-2026-61431

MEDIUM

PraisonAI before 4.6.78 Path Traversal via ContextGatherer

Title source: cna
STIX 2.1

Description

PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute paths or parent directory traversal sequences to read arbitrary files outside the workspace and include their contents in the generated context bundle.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-q7m5-3jmv-vm48)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-q7m5-3jmv-vm48
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI before 4.6.78 Path Traversal via ContextGatherer
https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-contextgatherer

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 17.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
MervinPraison/PraisonAI < 4.6.78
MervinPraison/PraisonAI 4.6.78
Published Jul 10, 2026
Tracked Since Jul 10, 2026