Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@
"aliases": [
"CVE-2026-56833"
],
"summary": "PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal",
"details": "# PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal\n\n## Summary\n\nPraisonAI's Dynamic Context module provides filesystem-backed history and\nterminal-log storage. The SDK reference describes the module as providing:\n\n- artifact storage for tool outputs, history, and terminal logs;\n- history persistence with search; and\n- terminal session logging.\n\nThe module also exports agent-callable tool factories:\n\n- `create_history_tools()` returns `history_search`, `history_tail`, and\n `history_get`.\n- `create_terminal_tools()` returns `terminal_tail`, `terminal_grep`, and\n `terminal_commands`.\n\nThose tools accept `run_id` and `agent_id` arguments from the tool caller. The\nunderlying stores join those values into filesystem paths without rejecting\nabsolute paths or `..` traversal:\n\n```python\nhistory_dir = self.base_dir / run_id / \"history\"\nreturn history_dir / f\"{agent_id}.jsonl\"\n```\n\n```python\nterminal_dir = self.base_dir / run_id / \"terminal\"\nreturn terminal_dir / f\"{agent_id}.log\"\n```\n\nBecause `run_id` can be an absolute path and `agent_id` can contain traversal,\na lower-trust prompt/user that can call these tools can read `.jsonl` and\n`.log` files outside the configured Dynamic Context base directory.\n\n## Affected Product\n\n- Repository: `MervinPraison/PraisonAI`\n- Ecosystem: `pip`\n- Package: `praisonai`\n- Component: Dynamic Context history and terminal tools\n- Current source paths:\n - `src/praisonai/praisonai/context/history_store.py`\n - `src/praisonai/praisonai/context/terminal_logger.py`\n- Latest PyPI version validated: `4.6.58`\n- Current `origin/main` validated:\n `1ad58ca02975ff1398efeda694ea2ab78f20cf3e`\n- Current `origin/main` tag validated: `v4.6.58`\n\nSuggested affected range:\n\n```text\npip:praisonai >= 3.8.1, <= 4.6.58\n```\n\nRepresentative local sweep:\n\n- `3.8.1`: vulnerable\n- `4.0.0`: vulnerable\n- `4.5.113`: vulnerable\n- `4.6.33`: vulnerable\n- `4.6.34`: vulnerable\n- `4.6.40`: vulnerable\n- `4.6.50`: vulnerable\n- `4.6.58`: vulnerable\n\n## Root Cause\n\n`HistoryStore._get_history_path()` and `TerminalLogger._get_log_path()` treat\nlogical identifiers as path segments, but never validate that the resolved path\nstays under `base_dir`.\n\nHistory path construction:\n\n```python\ndef _get_history_path(self, run_id: str, agent_id: str) -> Path:\n history_dir = self.base_dir / run_id / \"history\"\n history_dir.mkdir(parents=True, exist_ok=True)\n return history_dir / f\"{agent_id}.jsonl\"\n```\n\nTerminal path construction:\n\n```python\ndef _get_log_path(self, run_id: str, agent_id: str) -> Path:\n terminal_dir = self.base_dir / run_id / \"terminal\"\n terminal_dir.mkdir(parents=True, exist_ok=True)\n return terminal_dir / f\"{agent_id}.log\"\n```\n\nThe agent tools pass caller-controlled `run_id` and `agent_id` directly into\nthese helpers:\n\n```python\ndef history_tail(agent_id: str = \"default\", run_id: str = \"default\", count: int = 10) -> str:\n messages = history_store.get_last_messages(agent_id=agent_id, run_id=run_id, count=count)\n```\n\n```python\ndef terminal_tail(agent_id: str = \"default\", run_id: str = \"default\", lines: int = 50) -> str:\n return term_logger.tail_session(agent_id=agent_id, run_id=run_id, lines=lines)\n```\n\nThere is no check equivalent to:\n\n```python\nresolved = candidate.resolve()\nbase = self.base_dir.resolve()\nresolved.relative_to(base)\n```\n\nThere is also no identifier allowlist preventing `/`, `\\`, or `..` in\n`run_id` or `agent_id`.\n\n## Local PoV\n\nRun against the latest PyPI package:\n\n```bash\nuv run --with 'praisonai==4.6.58' \\\n python poc/pov_prai_cand_027_history_terminal_tools_path_traversal.py --json\n```\n\nThe PoV:\n\n1. Creates a temporary Dynamic Context base directory.\n2. Creates a separate outside directory containing `secret.jsonl` and\n `secret.log`.\n3. Creates legitimate in-base history and terminal log controls.\n4. Calls `history_tail()` and `history_get()` with\n `run_id=<outside-dir>` and `agent_id=../secret`.\n5. Calls `terminal_tail()` and `terminal_grep()` with the same traversal.\n6. Confirms the traversal paths resolve to files outside the configured base.\n\nObserved output summary from `evidence/pov-pypi-4.6.58.json`:\n\n```json\n{\n \"package\": \"praisonai\",\n \"package_version\": \"4.6.58\",\n \"controls\": {\n \"valid_history_read_works\": true,\n \"valid_terminal_read_works\": true,\n \"outside_history_file_outside_base_dir\": true,\n \"outside_terminal_file_outside_base_dir\": true,\n \"traversal_history_path_resolves_to_outside_file\": true,\n \"traversal_terminal_path_resolves_to_outside_file\": true\n },\n \"outside_history_tail\": \"Last 1 messages:\\\\n\\\\n[system]: PRAI-CAND-027-HISTORY-SECRET\",\n \"outside_terminal_tail\": \"PRAI-CAND-027-TERMINAL-SECRET\\\\nsecond line\\\\n\",\n \"outside_terminal_grep\": \"Found 1 matches:\\\\n\\\\n--- Line 1 ---\\\\n> PRAI-CAND-027-TERMINAL-SECRET\\\\n second line\",\n \"vulnerable\": true\n}\n```\n\nThe PoV is local-only. It does not start a server, contact a third-party\ntarget, or use real credentials.\n\n## Why This Is Not Intended Behavior\n\nThis report does not claim that history and terminal helpers should be unable\nto read legitimate history or terminal logs. The issue is narrower: logical\n`run_id` and `agent_id` values can escape the configured Dynamic Context base\ndirectory.\n\nThe controls show the intended boundary:\n\n- legitimate in-base history remains readable;\n- legitimate in-base terminal logs remain readable;\n- the outside `.jsonl` and `.log` files are not under the configured\n `base_dir`; and\n- the tools still disclose those outside files through traversal identifiers.\n\nThe official context reference describes history persistence and terminal\nlogging as filesystem-backed Dynamic Context features. The context security\ndocumentation also treats absolute paths, path traversal, and sensitive files\nas privacy/security risks. Reading files outside the configured context store\nconflicts with that documented boundary.\n\n## Impact\n\nIf a PraisonAI application exposes these Dynamic Context tools to untrusted or\nlower-trust prompts, the lower-trust caller can read files outside the\nconfigured context storage when the target file can be reached with the\ntool-imposed suffix:\n\n- `history_*` tools can disclose reachable `.jsonl` files;\n- `terminal_*` tools can disclose reachable `.log` files; and\n- cross-run or cross-agent context/history/logs can be disclosed if their path\n is known or guessable.\n\nThis can expose conversation history, prompts, terminal output, command logs,\ntokens, API keys, cloud credentials, operational data, or other secrets stored\nin JSONL/log files readable by the PraisonAI process.\n\nThe impact is confidentiality-only in the tested surface. Integrity and\navailability are not claimed for this report.\n\n## Severity\n\nSuggested severity: High.\n\nRationale:\n\n- `AV`: applies when an application exposes an agent with these tools over a\n network chat/API surface.\n- `AC`: the traversal needs only chosen `run_id` and `agent_id` values.\n- `PR`: an unauthenticated or public-facing agent endpoint can be exploited\n without an account. Deployments that require authenticated chat/API access\n may score this as `PR:L`.\n- `UI`: the attacker directly supplies the prompt/tool argument to the\n exposed agent surface.\n- `C`: conversation history and terminal logs can contain secrets and private\n operational data.\n- `I:N/A`: this report demonstrates read-only disclosure.\n\n## Remediation\n\nTreat `run_id` and `agent_id` as logical identifiers, not path components.\n\nRecommended fixes:\n\n1. Reject absolute paths, path separators, and traversal components in\n `run_id` and `agent_id`.\n2. Build candidate paths, call `.resolve()`, and reject any path that is not\n under `self.base_dir.resolve()`.\n3. Apply the same containment helper to history append/read/search/clear/export\n and terminal log/read/search/clear/export paths.\n4. Prefer opaque server-generated run and agent IDs in tool schemas.\n5. Add regression tests for absolute `run_id`, `../` in `run_id`, and `../` in\n `agent_id` for history and terminal tool factories.\n\nMinimal containment shape:\n\n```python\ndef _safe_child(self, *parts: str) -> Path:\n candidate = self.base_dir.joinpath(*parts).resolve()\n base = self.base_dir.resolve()\n try:\n candidate.relative_to(base)\n except ValueError as exc:\n raise PermissionError(\"Context path is outside configured base_dir\") from exc\n return candidate\n```\n\nPair this with an identifier allowlist, because `run_id` and `agent_id` should\nnot need filesystem syntax.",
"summary": "Dynamic Context History and Terminal Tools Read Files Outside Configured Storage via Path Traversal",
"details": "## Summary\n\nPraisonAI's Dynamic Context module provides filesystem-backed history and terminal-log storage. The SDK reference describes the module as providing:\n\n- artifact storage for tool outputs, history, and terminal logs;\n- history persistence with search; and\n- terminal session logging.\n\nThe module also exports agent-callable tool factories:\n\n- `create_history_tools()` returns `history_search`, `history_tail`, and `history_get`.\n- `create_terminal_tools()` returns `terminal_tail`, `terminal_grep`, and `terminal_commands`.\n\nThose tools accept `run_id` and `agent_id` arguments from the tool caller. The underlying stores join those values into filesystem paths without rejecting absolute paths or `..` traversal:\n\n```python\nhistory_dir = self.base_dir / run_id / \"history\"\nreturn history_dir / f\"{agent_id}.jsonl\"\n```\n\n```python\nterminal_dir = self.base_dir / run_id / \"terminal\"\nreturn terminal_dir / f\"{agent_id}.log\"\n```\n\nBecause `run_id` can be an absolute path and `agent_id` can contain traversal, a lower-trust prompt/user that can call these tools can read `.jsonl` and `.log` files outside the configured Dynamic Context base directory.\n\n## Technical Details\n\n`HistoryStore._get_history_path()` and `TerminalLogger._get_log_path()` treat logical identifiers as path segments, but never validate that the resolved path stays under `base_dir`.\n\nHistory path construction:\n\n```python\ndef _get_history_path(self, run_id: str, agent_id: str) -> Path:\n history_dir = self.base_dir / run_id / \"history\"\n history_dir.mkdir(parents=True, exist_ok=True)\n return history_dir / f\"{agent_id}.jsonl\"\n```\n\nTerminal path construction:\n\n```python\ndef _get_log_path(self, run_id: str, agent_id: str) -> Path:\n terminal_dir = self.base_dir / run_id / \"terminal\"\n terminal_dir.mkdir(parents=True, exist_ok=True)\n return terminal_dir / f\"{agent_id}.log\"\n```\n\nThe agent tools pass caller-controlled `run_id` and `agent_id` directly into these helpers:\n\n```python\ndef history_tail(agent_id: str = \"default\", run_id: str = \"default\", count: int = 10) -> str:\n messages = history_store.get_last_messages(agent_id=agent_id, run_id=run_id, count=count)\n```\n\n```python\ndef terminal_tail(agent_id: str = \"default\", run_id: str = \"default\", lines: int = 50) -> str:\n return term_logger.tail_session(agent_id=agent_id, run_id=run_id, lines=lines)\n```\n\nThere is no check equivalent to:\n\n```python\nresolved = candidate.resolve()\nbase = self.base_dir.resolve()\nresolved.relative_to(base)\n```\n\nThere is also no identifier allowlist preventing `/`, `\\`, or `..` in `run_id` or `agent_id`.\n\n### Why This Is Not Intended Behavior\n\nThis report does not claim that history and terminal helpers should be unable to read legitimate history or terminal logs. The issue is narrower: logical `run_id` and `agent_id` values can escape the configured Dynamic Context base directory.\n\nThe controls show the intended boundary:\n\n- legitimate in-base history remains readable;\n- legitimate in-base terminal logs remain readable;\n- the outside `.jsonl` and `.log` files are not under the configured `base_dir`; and\n- the tools still disclose those outside files through traversal identifiers.\n\nThe official context reference describes history persistence and terminal logging as filesystem-backed Dynamic Context features. The context security documentation also treats absolute paths, path traversal, and sensitive files as privacy/security risks. Reading files outside the configured context store conflicts with that documented boundary.\n\n## PoV\n\nRun against the latest PyPI package:\n\n```bash\nuv run --with 'praisonai==4.6.58' \\\n python poc/pov_poc.py --json\n```\n\nThe PoV:\n\n1. Creates a temporary Dynamic Context base directory.\n2. Creates a separate outside directory containing `secret.jsonl` and `secret.log`.\n3. Creates legitimate in-base history and terminal log controls.\n4. Calls `history_tail()` and `history_get()` with `run_id=<outside-dir>` and `agent_id=../secret`.\n5. Calls `terminal_tail()` and `terminal_grep()` with the same traversal.\n6. Confirms the traversal paths resolve to files outside the configured base.\n\nObserved output summary from `evidence/pov-pypi-4.6.58.json`:\n\n```json\n{\n \"package\": \"praisonai\",\n \"package_version\": \"4.6.58\",\n \"controls\": {\n \"valid_history_read_works\": true,\n \"valid_terminal_read_works\": true,\n \"outside_history_file_outside_base_dir\": true,\n \"outside_terminal_file_outside_base_dir\": true,\n \"traversal_history_path_resolves_to_outside_file\": true,\n \"traversal_terminal_path_resolves_to_outside_file\": true\n },\n \"outside_history_tail\": \"Last 1 messages:\\\\n\\\\n[system]: poc\",\n \"outside_terminal_tail\": \"poc\\\\nsecond line\\\\n\",\n \"outside_terminal_grep\": \"Found 1 matches:\\\\n\\\\n--- Line 1 ---\\\\n> poc\\\\n second line\",\n \"vulnerable\": true\n}\n```\n\nThe PoV is local-only. It does not start a server, contact a third-party target, or use real credentials.\n\n## PoC\n\nThe PoV section above contains the local reproduction command, input, and decisive output.\n\n## Impact\n\nIf a PraisonAI application exposes these Dynamic Context tools to untrusted or lower-trust prompts, the lower-trust caller can read files outside the configured context storage when the target file can be reached with the tool-imposed suffix:\n\n- `history_*` tools can disclose reachable `.jsonl` files;\n- `terminal_*` tools can disclose reachable `.log` files; and\n- cross-run or cross-agent context/history/logs can be disclosed if their path is known or guessable.\n\nThis can expose conversation history, prompts, terminal output, command logs, tokens, API keys, cloud credentials, operational data, or other secrets stored in JSONL/log files readable by the PraisonAI process.\n\nThe impact is confidentiality-only in the tested surface. Integrity and availability are not claimed for this report.\n\n### Severity\n\nSuggested severity: High.\n\nSuggested CVSS v3.1:\n\n```text\nCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n```\n\nRationale:\n\n- `AV:N`: applies when an application exposes an agent with these tools over a network chat/API surface.\n- `AC:L`: the traversal needs only chosen `run_id` and `agent_id` values.\n- `PR:N`: an unauthenticated or public-facing agent endpoint can be exploited without an account. Deployments that require authenticated chat/API access may score this as `PR:L`.\n- `UI:N`: the attacker directly supplies the prompt/tool argument to the exposed agent surface.\n- `C:H`: conversation history and terminal logs can contain secrets and private operational data.\n- `I:N/A:N`: this report demonstrates read-only disclosure.\n\n## Suggested Fix\n\nTreat `run_id` and `agent_id` as logical identifiers, not path components.\n\nRecommended fixes:\n\n1. Reject absolute paths, path separators, and traversal components in `run_id` and `agent_id`.\n2. Build candidate paths, call `.resolve()`, and reject any path that is not under `self.base_dir.resolve()`.\n3. Apply the same containment helper to history append/read/search/clear/export and terminal log/read/search/clear/export paths.\n4. Prefer opaque server-generated run and agent IDs in tool schemas.\n5. Add regression tests for absolute `run_id`, `../` in `run_id`, and `../` in `agent_id` for history and terminal tool factories.\n\nMinimal containment shape:\n\n```python\ndef _safe_child(self, *parts: str) -> Path:\n candidate = self.base_dir.joinpath(*parts).resolve()\n base = self.base_dir.resolve()\n try:\n candidate.relative_to(base)\n except ValueError as exc:\n raise PermissionError(\"Context path is outside configured base_dir\") from exc\n return candidate\n```\n\nPair this with an identifier allowlist, because `run_id` and `agent_id` should not need filesystem syntax.\n\n## Affected Package/Versions\n\n- Repository: `MervinPraison/PraisonAI`\n- Ecosystem: `pip`\n- Package: `praisonai`\n- Component: Dynamic Context history and terminal tools\n- Current source paths:\n- `src/praisonai/praisonai/context/history_store.py`\n- `src/praisonai/praisonai/context/terminal_logger.py`\n- Latest PyPI version validated: `4.6.58`\n- Current `origin/main` validated: `1ad58ca02975ff1398efeda694ea2ab78f20cf3e`\n- Current `origin/main` tag validated: `v4.6.58`\n\nSuggested affected range:\n\n```text\npip:praisonai >= 3.8.1, <= 4.6.58\n```\n\nRepresentative local sweep:\n\n- `3.8.1`: vulnerable\n- `4.0.0`: vulnerable\n- `4.5.113`: vulnerable\n- `4.6.33`: vulnerable\n- `4.6.34`: vulnerable\n- `4.6.40`: vulnerable\n- `4.6.50`: vulnerable\n- `4.6.58`: vulnerable\n\n## Advisory History\n\nVisible PraisonAI advisories and prior submissions were checked. This is distinct from nearby reports:\n\n- `GHSA-j7qx-p75m-wp7g` / poc covers Dynamic Context artifact helpers that accept raw `artifact_path` values. This report covers separate history and terminal tools that derive paths from `run_id` and `agent_id`.\n- `GHSA-766v-q9x3-g744` covers `praisonaiagents <= 1.5.114` example `MultiAgentLedger` / `MultiAgentMonitor` code. This report affects current `pip:praisonai` Dynamic Context `HistoryStore` and `TerminalLogger` tool factories.\n- `GHSA-9cr9-25q5-8prj` covers MCP CLI `workflow.show`, `workflow.validate`, and `deploy.validate` arbitrary file reads.\n- `GHSA-grrg-5cg9-58pf` covers `read_skill_file()` workspace-boundary bypass.\n- `GHSA-693f-pf34-72c5` and `GHSA-7j2f-xc8p-fjmq` cover file-tool path traversal surfaces, not Dynamic Context history/terminal tools.\n\nPrior reports do not cover `history_search`, `history_tail`, `history_get`, `terminal_tail`, `terminal_grep`, `terminal_commands`, `HistoryStore._get_history_path()`, or `TerminalLogger._get_log_path()`.\n\n## References\n\n- PraisonAI context module reference: `https://docs.praison.ai/docs/sdk/reference/praisonai/modules/context`\n- PraisonAI Dynamic Context Discovery: `https://docs.praison.ai/docs/features/dynamic-context-discovery`\n- PraisonAI Context Security & Redaction: `https://docs.praison.ai/docs/features/context-security-redaction` `https://github.com/MervinPraison/PraisonAI/security/policy`\n- PraisonAI GitHub advisories: `https://github.com/MervinPraison/PraisonAI/security/advisories`\n- Related but distinct prior advisory: `https://github.com/advisories/GHSA-766v-q9x3-g744`\n- MITRE CWE-22: `https://cwe.mitre.org/data/definitions/22.html`\n- MITRE CWE-200: `https://cwe.mitre.org/data/definitions/200.html`\n- FIRST CVSS v3.1 calculator: `https://www.first.org/cvss/calculator/3.1`\n",
"severity": [
{
"type": "CVSS_V3",
Expand Down Expand Up @@ -58,4 +58,4 @@
"github_reviewed_at": "2026-06-18T13:52:32Z",
"nvd_published_at": null
}
}
}