Description
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr. This exposes class, qualified-name, base-class, globals, and object-dictionary attributes to prompt-influenced code when approval is automatically granted, producing a high-impact read primitive without establishing a complete in-process execution chain. This issue is fixed in praisonaiagents 1.6.59.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A sandbox bypass in PraisonAI’s execute_code mode permits prompt‑influenced code to assemble runtime‑constructed blocklisted dunder names, and the str.format and str.format_map functions resolve dotted fields via C‑level attribute access that bypasses the _safe_getattr guard. This allows access to class, qualified‑name, base‑class, globals, and object‑dictionary attributes, producing a high‑impact read primitive without establishing a complete in‑process execution chain.

Affected Systems

The vulnerability affects MervinPraison’s PraisonAI agents software. Versions prior to 1.6.59 are vulnerable; all releases before that version allow the described sandbox bypass.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is classified as moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation, although the flaw can be triggered via a user‑supplied prompt that is automatically approved, making it reachable from untrusted input. The vulnerability is not listed in CISA KEV, yet the read of internal attributes could aid attackers in gathering information for downstream attacks. Due to the absence of a full execution chain, immediate remote code execution is unlikely, but the information disclosure can be a stepping stone for further compromise.

Generated by OpenCVE AI on September 21, 2026 at 00:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI agents to version 1.6.59 or later to eliminate the sandbox bypass.
  • Disable automatic approval of user prompts to reduce exposure to prompt‑driven exploitation.
  • Verify that the execute_code sandbox mode is enabled and review any custom code templates to ensure no unintended attribute dereferencing occurs.

Generated by OpenCVE AI on September 21, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pv2j-rghr-v5r9 PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonaiagents
Vendors & Products Mervinpraison
Mervinpraison praisonaiagents

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr. This exposes class, qualified-name, base-class, globals, and object-dictionary attributes to prompt-influenced code when approval is automatically granted, producing a high-impact read primitive without establishing a complete in-process execution chain. This issue is fixed in praisonaiagents 1.6.59.
Title PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mervinpraison Praisonaiagents
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:07:09.714Z

Reserved: 2026-06-24T00:33:17.707Z

Link: CVE-2026-57120

cve-icon Vulnrichment

Updated: 2026-09-16T15:07:03.406Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:05.607

Modified: 2026-09-16T16:17:12.970

Link: CVE-2026-57120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure