diff --git a/advisories/github-reviewed/2026/06/GHSA-f44v-7qgw-9gh9/GHSA-f44v-7qgw-9gh9.json b/advisories/github-reviewed/2026/06/GHSA-f44v-7qgw-9gh9/GHSA-f44v-7qgw-9gh9.json index 071b09e2783d..4c31f38d8a73 100644 --- a/advisories/github-reviewed/2026/06/GHSA-f44v-7qgw-9gh9/GHSA-f44v-7qgw-9gh9.json +++ b/advisories/github-reviewed/2026/06/GHSA-f44v-7qgw-9gh9/GHSA-f44v-7qgw-9gh9.json @@ -6,8 +6,8 @@ "aliases": [ "CVE-2026-57113" ], - "summary": "PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion", - "details": "## Summary\n\nPraisonAI's template loader accepts GitHub template URIs with refs, for example\n`github:owner/repo/template@v1.0.0`. The resolver stores the user-controlled\ntemplate path and ref verbatim, and the cache layer later joins those values into\n`~/.praison/cache/templates/github///