THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-ch89-h4r2-c8f8 (high) — PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

[GHSA] GHSA-ch89-h4r2-c8f8 (high) — PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

medgithub_advisoriesPublished 2026-08-25

GHSA-ch89-h4r2-c8f8 Severity: high CVE: CVE-2026-55540

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

### Summary PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` for agents) expose a `workspace` setting that the module itself treats as a path-traversal **security boundary** — `read_file`, `write_file`, `apply_diff`, and `search_replace`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-ch89-h4r2-c8f8