GHSA-p4pj-vh7h-6cqh: PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
An unauthenticated attacker can read arbitrary files on the server by supplying an absolute filesystem path in the agent_file field of the Jobs API. The field has no path validation, no allowlist, and no authentication is required to submit jobs.
References
Code Behaviors & Features
Detect and mitigate GHSA-p4pj-vh7h-6cqh with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →