Impact
A sandbox bypass in PraisonAI’s execute_code mode permits prompt‑influenced code to assemble runtime‑constructed blocklisted dunder names, and the str.format and str.format_map functions resolve dotted fields via C‑level attribute access that bypasses the _safe_getattr guard. This allows access to class, qualified‑name, base‑class, globals, and object‑dictionary attributes, producing a high‑impact read primitive without establishing a complete in‑process execution chain.
Affected Systems
The vulnerability affects MervinPraison’s PraisonAI agents software. Versions prior to 1.6.59 are vulnerable; all releases before that version allow the described sandbox bypass.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is classified as moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation, although the flaw can be triggered via a user‑supplied prompt that is automatically approved, making it reachable from untrusted input. The vulnerability is not listed in CISA KEV, yet the read of internal attributes could aid attackers in gathering information for downstream attacks. Due to the absence of a full execution chain, immediate remote code execution is unlikely, but the information disclosure can be a stepping stone for further compromise.
OpenCVE Enrichment
Github GHSA