Impact
PraisonAI's MentionsParser._process_file_mention accepts file‑mention values and falls back from a workspace‑relative resolution to Path(file_path) without any traversal, symlink, or workspace‑boundary validation. In versions prior to 1.6.59, this allowed an attacker who could supply a mention through a user prompt, bot request, or workflow to read arbitrary files the process can access, such as credentials, keys, environment files, source code, and system configuration. This vulnerability was fixed in praisonaiagents 1.6.59, but earlier releases remain at risk. The flaw corresponds to a Path Traversal vulnerability (CWE‑22).
Affected Systems
The vulnerability affects all instances of MervinPraison praisonaiagents older than version 1.6.59. Clients running praisonaiagents before the 1.6.59 release are susceptible; newer releases contain the fix that validates file paths correctly.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity vulnerability, while the EPSS score of <1% suggests a low probability of exploitation. The lack of a KEV listing points to limited evidence of widespread use. An attacker who can supply input to the MentionsParser—such as a user, bot, or workflow—can read arbitrary files, potentially leading to further compromise.
OpenCVE Enrichment
Github GHSA