GHSA-22cj-m4wf-fv2c: PraisonAI: path traversal in agent tools exposes credentials

GHSA-22cj-m4wf-fv2c HIGH
Published June 18, 2026
CISO Take

PraisonAI's Dynamic Context module fails to sanitize the `run_id` and `agent_id` parameters passed to its agent-callable history and terminal tools, enabling any caller who can invoke those tools to read arbitrary `.jsonl` and `.log` files accessible to the PraisonAI process. Every version from 3.8.1 through the current 4.6.58 is affected — covering the entire production lifetime of the Dynamic Context feature — and exploitation requires no authentication, no privileges, and zero AI/ML expertise, only crafted string arguments to the exposed tool interface. Conversation histories, system prompts, LLM API keys, cloud credentials, and terminal output stored as JSONL or log files are the primary exfiltration targets in typical agentic deployments, and in pipelines that process untrusted documents the attack surface extends to indirect exploitation via prompt injection. Upgrade to praisonai 4.6.59 immediately; if deferral is necessary, remove `create_history_tools()` and `create_terminal_tools()` from any agent tool registrations exposed to untrusted callers and tighten OS-level filesystem permissions on the PraisonAI process.

Sources: GitHub Advisory ATLAS

What is the risk?

High risk for organizations running PraisonAI with Dynamic Context enabled in public-facing or multi-tenant agentic applications. The CVSS 7.5 vector (AV:N/AC:L/PR:N/UI:N) is fully realized in deployments that expose agent tool APIs to external users, requiring no attacker credentials or user interaction. The trivial exploitation complexity is compounded by the breadth of the affected version range (3.8.1 through 4.6.58) and the sensitivity of data typically stored in agentic context logs. Indirect risk exists in agentic pipelines where prompt injection could trigger the traversal without the attacker ever directly calling the tool API. The 107 prior CVEs recorded against the same package indicate a pattern of accumulated security debt in PraisonAI that warrants heightened scrutiny before expanding its deployment footprint.

How does the attack unfold?

Tool Access
Attacker gains ability to invoke PraisonAI Dynamic Context tools (history_tail, terminal_tail, history_get, terminal_grep) either directly via a public agent API endpoint or indirectly through a prompt injection payload embedded in a document processed by the pipeline.
AML.T0053
Path Traversal Construction
Attacker supplies an absolute filesystem path as `run_id` and a `../` traversal sequence as `agent_id`, causing `_get_history_path()` or `_get_log_path()` to construct a resolved path that escapes the configured Dynamic Context `base_dir`.
AML.T0049
Unauthorized File Read
The tool reads the target `.jsonl` or `.log` file at the traversed path without any boundary containment check, returning its full contents to the caller in the tool response.
AML.T0037
Credential Exfiltration
Returned file contents — potentially containing LLM API keys, cloud credentials, conversation histories, or system prompts — are delivered to the attacker via the agent's normal response channel.
AML.T0086

What systems are affected?

Package Ecosystem Vulnerable Range Patched
PraisonAI pip >= 3.8.1, <= 4.6.58 4.6.59
1 dependents 68% patched ~14d to patch Full package profile →

Do you use PraisonAI? You're affected.

How severe is it?

CVSS 3.1
7.5 / 10
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
Trivial

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Unchanged
C High
I None
A None

What should I do?

6 steps
  1. Upgrade praisonai to version 4.6.59 (patched), which introduces _safe_child() path containment validation rejecting paths that resolve outside base_dir.

  2. If immediate upgrade is blocked, remove create_history_tools() and create_terminal_tools() from all agent tool registrations exposed to external or semi-trusted callers.

  3. Apply OS-level filesystem restrictions — chroot, seccomp, AppArmor profiles, or Docker volume scoping — to limit what files the PraisonAI process user account can read.

  4. Audit agent configurations to confirm run_id and agent_id are server-generated opaque identifiers never derived from user-controlled input.

  5. For detection, search application and API gateway logs for tool call payloads containing path separators (/, \, ..) in run_id or agent_id argument positions; flag and alert on any occurrence.

  6. Proactively rotate any LLM API keys, cloud credentials, and tokens that may have been stored in JSONL history or log files reachable by the affected deployment.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Art. 15 - Accuracy, robustness and cybersecurity
ISO 42001
8.4 - AI system security
NIST AI RMF
MANAGE 2.4 - Residual risks to individuals are monitored and managed
OWASP LLM Top 10
LLM06 - Excessive Agency

Frequently Asked Questions

What is GHSA-22cj-m4wf-fv2c?

PraisonAI's Dynamic Context module fails to sanitize the `run_id` and `agent_id` parameters passed to its agent-callable history and terminal tools, enabling any caller who can invoke those tools to read arbitrary `.jsonl` and `.log` files accessible to the PraisonAI process. Every version from 3.8.1 through the current 4.6.58 is affected — covering the entire production lifetime of the Dynamic Context feature — and exploitation requires no authentication, no privileges, and zero AI/ML expertise, only crafted string arguments to the exposed tool interface. Conversation histories, system prompts, LLM API keys, cloud credentials, and terminal output stored as JSONL or log files are the primary exfiltration targets in typical agentic deployments, and in pipelines that process untrusted documents the attack surface extends to indirect exploitation via prompt injection. Upgrade to praisonai 4.6.59 immediately; if deferral is necessary, remove `create_history_tools()` and `create_terminal_tools()` from any agent tool registrations exposed to untrusted callers and tighten OS-level filesystem permissions on the PraisonAI process.

Is GHSA-22cj-m4wf-fv2c actively exploited?

No confirmed active exploitation of GHSA-22cj-m4wf-fv2c has been reported, but organizations should still patch proactively.

How to fix GHSA-22cj-m4wf-fv2c?

1. Upgrade praisonai to version 4.6.59 (patched), which introduces `_safe_child()` path containment validation rejecting paths that resolve outside `base_dir`. 2. If immediate upgrade is blocked, remove `create_history_tools()` and `create_terminal_tools()` from all agent tool registrations exposed to external or semi-trusted callers. 3. Apply OS-level filesystem restrictions — chroot, seccomp, AppArmor profiles, or Docker volume scoping — to limit what files the PraisonAI process user account can read. 4. Audit agent configurations to confirm `run_id` and `agent_id` are server-generated opaque identifiers never derived from user-controlled input. 5. For detection, search application and API gateway logs for tool call payloads containing path separators (`/`, `\`, `..`) in `run_id` or `agent_id` argument positions; flag and alert on any occurrence. 6. Proactively rotate any LLM API keys, cloud credentials, and tokens that may have been stored in JSONL history or log files reachable by the affected deployment.

What systems are affected by GHSA-22cj-m4wf-fv2c?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, multi-agent systems, agentic pipelines, RAG pipelines, LLM application backends.

What is the CVSS score for GHSA-22cj-m4wf-fv2c?

GHSA-22cj-m4wf-fv2c has a CVSS v3.1 base score of 7.5 (HIGH).

What is the AI security impact?

Affected AI Architectures

agent frameworksmulti-agent systemsagentic pipelinesRAG pipelinesLLM application backends

MITRE ATLAS Techniques

AML.T0037 Data from Local System
AML.T0051.000 Direct
AML.T0053 AI Agent Tool Invocation
AML.T0086 Exfiltration via AI Agent Tool Invocation

Compliance Controls Affected

EU AI Act: Art. 15
ISO 42001: 8.4
NIST AI RMF: MANAGE 2.4
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

# PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal ## Summary PraisonAI's Dynamic Context module provides filesystem-backed history and terminal-log storage. The SDK reference describes the module as providing: - artifact storage for tool outputs, history, and terminal logs; - history persistence with search; and - terminal session logging. The module also exports agent-callable tool factories: - `create_history_tools()` returns `history_search`, `history_tail`, and `history_get`. - `create_terminal_tools()` returns `terminal_tail`, `terminal_grep`, and `terminal_commands`. Those tools accept `run_id` and `agent_id` arguments from the tool caller. The underlying stores join those values into filesystem paths without rejecting absolute paths or `..` traversal: ```python history_dir = self.base_dir / run_id / "history" return history_dir / f"{agent_id}.jsonl" ``` ```python terminal_dir = self.base_dir / run_id / "terminal" return terminal_dir / f"{agent_id}.log" ``` Because `run_id` can be an absolute path and `agent_id` can contain traversal, a lower-trust prompt/user that can call these tools can read `.jsonl` and `.log` files outside the configured Dynamic Context base directory. ## Affected Product - Repository: `MervinPraison/PraisonAI` - Ecosystem: `pip` - Package: `praisonai` - Component: Dynamic Context history and terminal tools - Current source paths: - `src/praisonai/praisonai/context/history_store.py` - `src/praisonai/praisonai/context/terminal_logger.py` - Latest PyPI version validated: `4.6.58` - Current `origin/main` validated: `1ad58ca02975ff1398efeda694ea2ab78f20cf3e` - Current `origin/main` tag validated: `v4.6.58` Suggested affected range: ```text pip:praisonai >= 3.8.1, <= 4.6.58 ``` Representative local sweep: - `3.8.1`: vulnerable - `4.0.0`: vulnerable - `4.5.113`: vulnerable - `4.6.33`: vulnerable - `4.6.34`: vulnerable - `4.6.40`: vulnerable - `4.6.50`: vulnerable - `4.6.58`: vulnerable ## Root Cause `HistoryStore._get_history_path()` and `TerminalLogger._get_log_path()` treat logical identifiers as path segments, but never validate that the resolved path stays under `base_dir`. History path construction: ```python def _get_history_path(self, run_id: str, agent_id: str) -> Path: history_dir = self.base_dir / run_id / "history" history_dir.mkdir(parents=True, exist_ok=True) return history_dir / f"{agent_id}.jsonl" ``` Terminal path construction: ```python def _get_log_path(self, run_id: str, agent_id: str) -> Path: terminal_dir = self.base_dir / run_id / "terminal" terminal_dir.mkdir(parents=True, exist_ok=True) return terminal_dir / f"{agent_id}.log" ``` The agent tools pass caller-controlled `run_id` and `agent_id` directly into these helpers: ```python def history_tail(agent_id: str = "default", run_id: str = "default", count: int = 10) -> str: messages = history_store.get_last_messages(agent_id=agent_id, run_id=run_id, count=count) ``` ```python def terminal_tail(agent_id: str = "default", run_id: str = "default", lines: int = 50) -> str: return term_logger.tail_session(agent_id=agent_id, run_id=run_id, lines=lines) ``` There is no check equivalent to: ```python resolved = candidate.resolve() base = self.base_dir.resolve() resolved.relative_to(base) ``` There is also no identifier allowlist preventing `/`, `\`, or `..` in `run_id` or `agent_id`. ## Local PoV Run against the latest PyPI package: ```bash uv run --with 'praisonai==4.6.58' \ python poc/pov_prai_cand_027_history_terminal_tools_path_traversal.py --json ``` The PoV: 1. Creates a temporary Dynamic Context base directory. 2. Creates a separate outside directory containing `secret.jsonl` and `secret.log`. 3. Creates legitimate in-base history and terminal log controls. 4. Calls `history_tail()` and `history_get()` with `run_id=<outside-dir>` and `agent_id=../secret`. 5. Calls `terminal_tail()` and `terminal_grep()` with the same traversal. 6. Confirms the traversal paths resolve to files outside the configured base. Observed output summary from `evidence/pov-pypi-4.6.58.json`: ```json { "package": "praisonai", "package_version": "4.6.58", "controls": { "valid_history_read_works": true, "valid_terminal_read_works": true, "outside_history_file_outside_base_dir": true, "outside_terminal_file_outside_base_dir": true, "traversal_history_path_resolves_to_outside_file": true, "traversal_terminal_path_resolves_to_outside_file": true }, "outside_history_tail": "Last 1 messages:\\n\\n[system]: PRAI-CAND-027-HISTORY-SECRET", "outside_terminal_tail": "PRAI-CAND-027-TERMINAL-SECRET\\nsecond line\\n", "outside_terminal_grep": "Found 1 matches:\\n\\n--- Line 1 ---\\n> PRAI-CAND-027-TERMINAL-SECRET\\n second line", "vulnerable": true } ``` The PoV is local-only. It does not start a server, contact a third-party target, or use real credentials. ## Why This Is Not Intended Behavior This report does not claim that history and terminal helpers should be unable to read legitimate history or terminal logs. The issue is narrower: logical `run_id` and `agent_id` values can escape the configured Dynamic Context base directory. The controls show the intended boundary: - legitimate in-base history remains readable; - legitimate in-base terminal logs remain readable; - the outside `.jsonl` and `.log` files are not under the configured `base_dir`; and - the tools still disclose those outside files through traversal identifiers. The official context reference describes history persistence and terminal logging as filesystem-backed Dynamic Context features. The context security documentation also treats absolute paths, path traversal, and sensitive files as privacy/security risks. Reading files outside the configured context store conflicts with that documented boundary. ## Impact If a PraisonAI application exposes these Dynamic Context tools to untrusted or lower-trust prompts, the lower-trust caller can read files outside the configured context storage when the target file can be reached with the tool-imposed suffix: - `history_*` tools can disclose reachable `.jsonl` files; - `terminal_*` tools can disclose reachable `.log` files; and - cross-run or cross-agent context/history/logs can be disclosed if their path is known or guessable. This can expose conversation history, prompts, terminal output, command logs, tokens, API keys, cloud credentials, operational data, or other secrets stored in JSONL/log files readable by the PraisonAI process. The impact is confidentiality-only in the tested surface. Integrity and availability are not claimed for this report. ## Severity Suggested severity: High. Rationale: - `AV`: applies when an application exposes an agent with these tools over a network chat/API surface. - `AC`: the traversal needs only chosen `run_id` and `agent_id` values. - `PR`: an unauthenticated or public-facing agent endpoint can be exploited without an account. Deployments that require authenticated chat/API access may score this as `PR:L`. - `UI`: the attacker directly supplies the prompt/tool argument to the exposed agent surface. - `C`: conversation history and terminal logs can contain secrets and private operational data. - `I:N/A`: this report demonstrates read-only disclosure. ## Remediation Treat `run_id` and `agent_id` as logical identifiers, not path components. Recommended fixes: 1. Reject absolute paths, path separators, and traversal components in `run_id` and `agent_id`. 2. Build candidate paths, call `.resolve()`, and reject any path that is not under `self.base_dir.resolve()`. 3. Apply the same containment helper to history append/read/search/clear/export and terminal log/read/search/clear/export paths. 4. Prefer opaque server-generated run and agent IDs in tool schemas. 5. Add regression tests for absolute `run_id`, `../` in `run_id`, and `../` in `agent_id` for history and terminal tool factories. Minimal containment shape: ```python def _safe_child(self, *parts: str) -> Path: candidate = self.base_dir.joinpath(*parts).resolve() base = self.base_dir.resolve() try: candidate.relative_to(base) except ValueError as exc: raise PermissionError("Context path is outside configured base_dir") from exc return candidate ``` Pair this with an identifier allowlist, because `run_id` and `agent_id` should not need filesystem syntax.

Exploitation Scenario

An attacker targeting a public-facing PraisonAI chat application sends a message invoking `history_tail` with `run_id` set to an absolute directory path such as `/home/app/.secrets` and `agent_id` set to `../openai_key`, causing the tool to construct `/home/app/.secrets/history/../openai_key.jsonl` and return its contents directly in the agent's response. In a more sophisticated variant, a malicious PDF or web page processed by a PraisonAI RAG pipeline contains an embedded prompt injection payload instructing the agent to call `terminal_grep` with traversal arguments targeting `/proc/1/environ` or an adjacent credential store, silently exfiltrating environment variables — including LLM API keys and cloud provider secrets — and encoding them in the agent's next natural-language response to the attacker.

Weaknesses (CWE)

CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor: The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • [Architecture and Design] Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Timeline

Published
June 18, 2026
Last Modified
June 18, 2026
First Seen
June 18, 2026

Related Vulnerabilities