Impact
PraisonAI runs skill scripts without validating the path, allowing an attacker to supply an absolute file path and execute any script on the host. This enables remote code execution because the script is executed with the application’s privileges. The weakness is an arbitrary file path traversal (CWE-22).
Affected Systems
MervinPraison’s PraisonAI products prior to version 1.6.78 are vulnerable. Any installation of PraisonAI before this release that exposes the SkillTools interface is impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of The vulnerability is not currently listed in CISA’s KEV catalog. Exploitation requires remote access to the a script file path. The attack likely occurs over the network, but the exact vector is not explicitly documented; it is inferred from the ability to invoke run_skill_script remotely.
OpenCVE Enrichment