Impact
PraisonAI before version 4.6.78 contains a path traversal flaw (CWE‑22) in the ContextGatherer component, which accepts include paths from .praisoncontext and .praisoninclude files without proper validation. An attacker who can supply absolute paths or use parent directory traversal sequences may cause the application to read and include any file located outside the intended workspace. This can expose sensitive data, configuration files, or other secrets that the application has access to.
Affected Systems
The vulnerability affects MervinPraison’s PraionAI software prior to version 4.6.78. No other vendors or product variants were indicated in the CNA data.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity; the EPSS score of < 1%, and the flaw is not listed in CISA KEV, suggesting it is not a widely exploited issue yet. The attack would require compromise of the host or tampering with the application’s context files, meaning the threat profile is best described as a moderate risk to confidentiality with potential local or delegated access. Given the nature of the path traversal, the flaw is straightforward to exploit once the attacker can influence the input files, and remediation should be prioritized.
OpenCVE Enrichment