Description
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly isolated commands to reach localhost, internal services, cloud metadata, or external hosts and potentially exfiltrate data. An initial remediation was released in version 1.7.2.
Published: 2026-09-15
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized network access with potential data exfiltration
Action: Patch Immediately
AI Analysis

Impact

PraisonAI’s SandboxExecutor uses a network‑isolated mode that injects bad proxy environment variables rather than creating a true OS‑level network barrier, and the mode does not block processes that ignore those variables. This flaw allows sandboxed commands to open network sockets directly, reaching localhost, internal services, cloud metadata, or arbitrary external hosts, thereby exposing command inputs, output data, or metadata to attackers. The weakness is a breach of network access control and an improper enforcement of security boundaries, corresponding to CWE‑653 and CWE‑693.

Affected Systems

The issue exists in PraisonAI releases from 1.2.3 up to and including 1.7.2. All versions prior to 1.7.2 are vulnerable; upgrading to 1.7.2 or later removes the problem.

Risk and Exploitability

The CVSS score of 7.6 classifies the flaw as high severity, while an EPSS score of less than 1% indicates a very low probability of exploitation at present. Based on the description, it is inferred that the attacker must have the ability to execute code within the sandboxed context; once inside, an attacker can bypass the isolation to exfiltrate data. The vulnerability is exercised by code running inside the sandbox, so the immediate attacker needs to exploit code execution or supply malicious inputs to run within the sandbox. The flaw is not listed in the CISA KEV catalog, so no public exploit remains known, but the potential impact warrants prompt action.

Generated by OpenCVE AI on September 17, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 1.7.2 or later to install the built‑in network boundary fix.
  • If an upgrade is not immediately feasible, disable the network‑isolated mode or enforce system‑level proxy settings to block direct socket connections from sandboxed processes.
  • Continuously monitor outbound traffic from sandboxed commands for unexpected connections and investigate any anomalies.

Generated by OpenCVE AI on September 17, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gqmf-56h7-rrpf npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly isolated commands to reach localhost, internal services, cloud metadata, or external hosts and potentially exfiltrate data. An initial remediation was released in version 1.7.2.
Title PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
Weaknesses CWE-653
CWE-693
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:43:30.886Z

Reserved: 2026-06-24T00:33:17.708Z

Link: CVE-2026-57135

cve-icon Vulnrichment

Updated: 2026-09-15T12:43:25.879Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:10.733

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-653

    Improper Isolation or Compartmentalization

  • CWE-693

    Protection Mechanism Failure