CVE-2026-60088
published 2026-07-11CVE-2026-60088: PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers…
PriorityP427medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.18%
8.0th percentile
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai | < 4.6.78 | 4.6.78 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace.
ghsa_unreviewed·2026-07-11
CVE-2026-60088 [MEDIUM] CWE-22 PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace.
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model prompts.
VulDB
MervinPraison PraisonAI up to 4.6.77 File Path outside_secret.txt validate path path traversal (EUVD-2026-43174)
vuldb·2026-07-11·CVSS 5.5
CVE-2026-60088 [MEDIUM] MervinPraison PraisonAI up to 4.6.77 File Path outside_secret.txt validate path path traversal (EUVD-2026-43174)
A vulnerability labeled as problematic has been found in MervinPraison PraisonAI up to 4.6.77. This affects the function validate of the file outside_secret.txt of the component File Path. The manipulation of the argument path results in path traversal.
This vulnerability is cataloged as CVE-2026-60088. The attack must be initiated from a local position. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/MervinPraison/PraisonAI/commit/3aa9cbc2bd49c23a32be0a89a5e620d13d843eabhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xpx6-x8c2-mw5whttps://www.vulncheck.com/advisories/praisonai-before-path-traversal-via-custom-commandshttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xpx6-x8c2-mw5w
2026-07-11
Published