PYSEC-2026-3888

    Dashboard / Vulnerabilities / PYSEC-2026-3888

    PYSEC-2026-3888

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

    Details: ### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` for agents) expose a `workspace` setting that the module itself treats as a path-traversal **security boundary** — `read_file`, `write_file`, `apply_diff`, and `search_replace` explicitly call `is_path_within_directory()` and return `"… is outside the workspace"` on violations. That boundary is enforced **unsoundly and inconsistently**: 1. The containment helper uses `os.path.abspath()`, not `realpath()`/`Path.resolve()`. A symlink located **inside** the workspace whose target is **outside** has an `abspath()` that is still inside the workspace, so it passes the check while `open()` follows the link. This bypasses read, write, apply_diff, and search_replace (CWE-59). 2. `list_files()` resolves `path` against the workspace but **never** calls the containment helper at all — `../` and absolute paths escape directly (CWE-22). 3. `execute_command()` takes a `workspace` argument documented "for security validation" but performs **no** `cwd` containment check; `code_execute_command()` resolves a relative `cwd` against the workspace and also never validates it (and never even passes `workspace` to the low-level helper). A relative `cwd="../outside"` runs commands from outside the workspace (CWE-22). An attacker who can influence an agent that has these tools attached (untrusted prompt, indirect prompt injection, or a server-exposed agent) can read, overwrite, list, and execute from outside the configured workspace, bounded only by the process user's filesystem permissions. ## Technical Detail ### 1. Unsound containment helper (symlink bypass — CWE-59) ```python # src/praisonai/praisonai/code/utils/file_utils.py — is_path_within_directory() abs_file = os.path.abspath(file_path) # does NOT resolve symlinks abs_dir = os.path.abspath(directory) if not abs_dir.endswith(os.sep): abs_dir += os.sep return abs_file.startswith(abs_dir) or abs_file == abs_dir.rstrip(os.sep) ``` `read_file`/`write_file`/`apply_diff`/`search_replace` call this with the configured workspace (e.g. `read_file.py`: `# Security check - ensure path is within workspace`). Because `abspath()` does not canonicalize symlinks, a link at `WORKSPACE/link_to_secret.txt` → `/outside/secret.txt` has `abspath` `WORKSPACE/link_to_secret.txt` (inside) and passes, while `open()` follows it to the real outside target. ### 2. `list_files()` has no containment check (CWE-22) ```python # src/praisonai/praisonai/code/tools/list_files.py if workspace and not os.path.isabs(path): abs_path = os.path.abspath(os.path.join(workspace, path)) # ../ collapses out of workspace else: abs_path = os.path.abspath(path) # absolute path used as-is # ... os.path.isdir(abs_path) then listed. is_path_within_directory() is NEVER called. ``` ### 3. `execute_command()` never validates `cwd` (CWE-22) ```python # src/praisonai/praisonai/code/tools/execute_command.py — workspace param doc: "for security validation" if cwd: if workspace and not os.path.isabs(cwd): work_dir = os.path.abspath(os.path.join(workspace, cwd)) # ../ escapes; no containment check else: work_dir = os.path.abspath(cwd) # subprocess.run(args, cwd=work_dir, ...) # no is_path_within_directory() anywhere ``` ```python # src/praisonai/praisonai/code/agent_tools.py — code_execute_command() if work_dir and _workspace_root and not os.path.isabs(work_dir): work_dir = os.path.join(_workspace_root, work_dir) # joins, never validates result = _execute_command(command=command, cwd=work_dir, timeout=120) # workspace not even passed ``` Note: `execute_command` rejects `shell=True` and runs `shlex.split(command)` via `subprocess.run` (no shell), so shell metacharacters (`&&`, `>`, pipes) do not work — but any binary still runs with attacker-chosen argv **from the escaped cwd**, which is sufficient to read/write outside the workspace. ### The workspace is an intended boundary (pre-empts "by design") The module asserts this control itself: `read_file.py` "Security check - ensure path is within workspace"; `write_file.py` "default workspace is cwd so relative paths cannot escape"; `is_path_within_directory` docstring "(prevents path traversal)"; `execute_command` `workspace` param "for security validation". The bug is that the asserted control is unsound (abspath vs realpath) and not applied to `list_files`/`execute_command` cwd. ## Proof of Concept Self-contained, local temp fixtures only; no network, no untrusted commands. Real `praisonai.code` agent tools were called. ``` workspace = /tmp/.../workspace outside = /tmp/.../outside [1] baseline plain ../ read -> BLOCKED: "Path '../outside/secret.txt' is outside the workspace" [2] symlink read (in-WS link) -> SUCCESS: returned "SECRET_OUTSIDE_WORKSPACE" [3] symlink write (in-WS link) -> SUCCESS: outside file now contains "OVERWRITTEN_VIA_SYMLINK" [4] code_list_files("../outside") -> SUCCESS: "Contents of ../outside: 📄 secret.txt" [5] code_execute_command(cwd="../outside","pwd") -> SUCCESS: stdout "/tmp/.../outside" [6] code_execute_command(cwd="../outside", python3 -c open('planted.txt','w')...) -> SUCCESS: new file created OUTSIDE workspace, "PWNED_OUTSIDE_WORKSPACE" ``` Steps 2–6 each cross the configured workspace boundary; step 1 shows the plain-`../` guard that the symlink and unscoped vectors bypass. ## Impact - **Confidentiality**: read files outside the workspace (in-workspace symlink; or list/enumerate outside dirs via `list_files`). - **Integrity**: overwrite outside files via symlink; create/modify files outside the workspace via `execute_command` running in an escaped cwd. - **Execution boundary**: run arbitrary available binaries (argv-controlled) from a directory outside the workspace. Bounded by the process user's permissions. In a code-agent or server-exposed agent processing untrusted input, this exposes secrets / project-adjacent / host files and breaks the project-boundary integrity guarantee the workspace setting advertises. ## Suggested Fix - Replace `is_path_within_directory()` with a `realpath()` / `Path.resolve()`-based containment check, and compare with `os.path.commonpath()` rather than `startswith`. - Apply that check consistently to every file path, directory path, backup path, diff/search-replace target, **and command working directory**, after full canonicalization (resolve the symlink's real target, not the link path). - `list_files()`: reject absolute paths and `../` escapes when `workspace` is set. - `execute_command()`: validate `cwd` containment when `workspace` is set; `code_execute_command()` should pass `_workspace_root` to the low-level helper or validate itself. - Regression tests: symlink read/write/diff/search-replace to outside targets; `list_files("../outside", workspace=…)`; `execute_command(cwd="../outside", workspace=…)`; absolute outside paths with a workspace set.

    Affected packages

    Package

    Name: praisonai

    Purl: pkg:pypi/praisonai

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.6.58

    Affected versions

    0.0.1
    0.0.10
    0.0.11
    0.0.12
    0.0.13
    0.0.14
    0.0.15
    0.0.16
    0.0.17
    0.0.18
    0.0.19
    0.0.2
    0.0.20
    0.0.21
    0.0.22
    0.0.23
    0.0.24
    0.0.25
    0.0.26
    0.0.27
    0.0.28
    0.0.29
    0.0.3
    0.0.30
    0.0.31
    0.0.32
    0.0.33
    0.0.34
    0.0.35
    0.0.36
    0.0.37
    0.0.38
    0.0.39
    0.0.4
    0.0.40
    0.0.41
    0.0.42
    0.0.43
    0.0.44
    0.0.45
    0.0.46
    0.0.47
    0.0.48
    0.0.49
    0.0.5
    0.0.50
    0.0.52
    0.0.53
    0.0.54
    0.0.55
    0.0.56
    0.0.57
    0.0.58
    0.0.59
    0.0.59rc11
    0.0.59rc2
    0.0.59rc3
    0.0.59rc5
    0.0.59rc6
    0.0.59rc7
    0.0.59rc8
    0.0.59rc9
    0.0.6
    0.0.61
    0.0.64
    0.0.65
    0.0.66
    0.0.67
    0.0.68
    0.0.69
    0.0.7
    0.0.70
    0.0.71
    0.0.72
    0.0.73
    0.0.74
    0.0.8
    0.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-3888 | CVE-DB