CVE-2026-56833
HIGHCVE-2026-56833 is a high-severity (CVSS 7.5) vulnerability in praisonai. O3 Security confirms whether CVE-2026-56833 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
Real-World Exposure
praisonaiReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
Summary
PraisonAI's Dynamic Context module provides filesystem-backed history and terminal-log storage. The SDK reference describes the module as providing:
- artifact storage for tool outputs, history, and terminal logs;
- history persistence with search; and
- terminal session logging.
The module also exports agent-callable tool factories:
create_history_tools()returnshistory_search,history_tail, andhistory_get.create_terminal_tools()returnsterminal_tail,terminal_grep, andterminal_commands.
Those tools accept run_id and agent_id arguments from the tool caller. The
underlying stores join those values into filesystem paths without rejecting
absolute paths or .. traversal:
history_dir = self.base_dir / run_id / "history"
return history_dir / f"{agent_id}.jsonl"
terminal_dir = self.base_dir / run_id / "terminal"
return terminal_dir / f"{agent_id}.log"
Because run_id can be an absolute path and agent_id can contain traversal,
a lower-trust prompt/user that can call these tools can read .jsonl and
.log files outside the configured Dynamic Context base directory.
Affected Product
- Repository:
MervinPraison/PraisonAI - Ecosystem:
pip - Package:
praisonai - Component: Dynamic Context history and terminal tools
- Current source paths:
src/praisonai/praisonai/context/history_store.pysrc/praisonai/praisonai/context/terminal_logger.py
- Latest PyPI version validated:
4.6.58 - Current
origin/mainvalidated:1ad58ca02975ff1398efeda694ea2ab78f20cf3e - Current
origin/maintag validated:v4.6.58
Suggested affected range:
pip:praisonai >= 3.8.1, <= 4.6.58
Representative local sweep:
3.8.1: vulnerable4.0.0: vulnerable4.5.113: vulnerable4.6.33: vulnerable4.6.34: vulnerable4.6.40: vulnerable4.6.50: vulnerable4.6.58: vulnerable
Root Cause
HistoryStore._get_history_path() and TerminalLogger._get_log_path() treat
logical identifiers as path segments, but never validate that the resolved path
stays under base_dir.
History path construction:
def _get_history_path(self, run_id: str, agent_id: str) -> Path:
history_dir = self.base_dir / run_id / "history"
history_dir.mkdir(parents=True, exist_ok=True)
return history_dir / f"{agent_id}.jsonl"
Terminal path construction:
def _get_log_path(self, run_id: str, agent_id: str) -> Path:
terminal_dir = self.base_dir / run_id / "terminal"
terminal_dir.mkdir(parents=True, exist_ok=True)
return terminal_dir / f"{agent_id}.log"
The agent tools pass caller-controlled run_id and agent_id directly into
these helpers:
def history_tail(agent_id: str = "default", run_id: str = "default", count: int = 10) -> str:
messages = history_store.get_last_messages(agent_id=agent_id, run_id=run_id, count=count)
def terminal_tail(agent_id: str = "default", run_id: str = "default", lines: int = 50) -> str:
return term_logger.tail_session(agent_id=agent_id, run_id=run_id, lines=lines)
There is no check equivalent to:
resolved = candidate.resolve()
base = self.base_dir.resolve()
resolved.relative_to(base)
There is also no identifier allowlist preventing /, \, or .. in
run_id or agent_id.
Local PoV
Run against the latest PyPI package:
uv run --with 'praisonai==4.6.58' \
python poc/pov_prai_cand_027_history_terminal_tools_path_traversal.py --json
The PoV:
- Creates a temporary Dynamic Context base directory.
- Creates a separate outside directory containing
secret.jsonlandsecret.log. - Creates legitimate in-base history and terminal log controls.
- Calls
history_tail()andhistory_get()withrun_id=<outside-dir>andagent_id=../secret. - Calls
terminal_tail()andterminal_grep()with the same traversal. - Confirms the traversal paths resolve to files outside the configured base.
Observed output summary from evidence/pov-pypi-4.6.58.json:
{
"package": "praisonai",
"package_version": "4.6.58",
"controls": {
"valid_history_read_works": true,
"valid_terminal_read_works": true,
"outside_history_file_outside_base_dir": true,
"outside_terminal_file_outside_base_dir": true,
"traversal_history_path_resolves_to_outside_file": true,
"traversal_terminal_path_resolves_to_outside_file": true
},
"outside_history_tail": "Last 1 messages:\\n\\n[system]: PRAI-CAND-027-HISTORY-SECRET",
"outside_terminal_tail": "PRAI-CAND-027-TERMINAL-SECRET\\nsecond line\\n",
"outside_terminal_grep": "Found 1 matches:\\n\\n--- Line 1 ---\\n> PRAI-CAND-027-TERMINAL-SECRET\\n second line",
"vulnerable": true
}
The PoV is local-only. It does not start a server, contact a third-party target, or use real credentials.
Why This Is Not Intended Behavior
This report does not claim that history and terminal helpers should be unable
to read legitimate history or terminal logs. The issue is narrower: logical
run_id and agent_id values can escape the configured Dynamic Context base
directory.
The controls show the intended boundary:
- legitimate in-base history remains readable;
- legitimate in-base terminal logs remain readable;
- the outside
.jsonland.logfiles are not under the configuredbase_dir; and - the tools still disclose those outside files through traversal identifiers.
The official context reference describes history persistence and terminal logging as filesystem-backed Dynamic Context features. The context security documentation also treats absolute paths, path traversal, and sensitive files as privacy/security risks. Reading files outside the configured context store conflicts with that documented boundary.
Impact
If a PraisonAI application exposes these Dynamic Context tools to untrusted or lower-trust prompts, the lower-trust caller can read files outside the configured context storage when the target file can be reached with the tool-imposed suffix:
history_*tools can disclose reachable.jsonlfiles;terminal_*tools can disclose reachable.logfiles; and- cross-run or cross-agent context/history/logs can be disclosed if their path is known or guessable.
This can expose conversation history, prompts, terminal output, command logs, tokens, API keys, cloud credentials, operational data, or other secrets stored in JSONL/log files readable by the PraisonAI process.
The impact is confidentiality-only in the tested surface. Integrity and availability are not claimed for this report.
Severity
Suggested severity: High.
Rationale:
AV: applies when an application exposes an agent with these tools over a network chat/API surface.AC: the traversal needs only chosenrun_idandagent_idvalues.PR: an unauthenticated or public-facing agent endpoint can be exploited without an account. Deployments that require authenticated chat/API access may score this asPR:L.UI: the attacker directly supplies the prompt/tool argument to the exposed agent surface.C: conversation history and terminal logs can contain secrets and private operational data.I:N/A: this report demonstrates read-only disclosure.
Remediation
Treat run_id and agent_id as logical identifiers, not path components.
Recommended fixes:
- Reject absolute paths, path separators, and traversal components in
run_idandagent_id. - Build candidate paths, call
.resolve(), and reject any path that is not underself.base_dir.resolve(). - Apply the same containment helper to history append/read/search/clear/export and terminal log/read/search/clear/export paths.
- Prefer opaque server-generated run and agent IDs in tool schemas.
- Add regression tests for absolute
run_id,../inrun_id, and../inagent_idfor history and terminal tool factories.
Minimal containment shape:
def _safe_child(self, *parts: str) -> Path:
candidate = self.base_dir.joinpath(*parts).resolve()
base = self.base_dir.resolve()
try:
candidate.relative_to(base)
except ValueError as exc:
raise PermissionError("Context path is outside configured base_dir") from exc
return candidate
Pair this with an identifier allowlist, because run_id and agent_id should
not need filesystem syntax.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | praisonai | ≥ 3.8.1&&< 4.6.59 | 4.6.59 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for praisonai. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.
Fix
Update praisonai to 4.6.59 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-56833 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 pinpoints whether CVE-2026-56833 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.
Tailored to CVE-2026-56833. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2026-56833 in your dependencies?
O3 detects CVE-2026-56833 across PyPI dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.