Impact
PraisonAI’s SandboxExecutor uses a network‑isolated mode that injects bad proxy environment variables rather than creating a true OS‑level network barrier, and the mode does not block processes that ignore those variables. This flaw allows sandboxed commands to open network sockets directly, reaching localhost, internal services, cloud metadata, or arbitrary external hosts, thereby exposing command inputs, output data, or metadata to attackers. The weakness is a breach of network access control and an improper enforcement of security boundaries, corresponding to CWE‑653 and CWE‑693.
Affected Systems
The issue exists in PraisonAI releases from 1.2.3 up to and including 1.7.2. All versions prior to 1.7.2 are vulnerable; upgrading to 1.7.2 or later removes the problem.
Risk and Exploitability
The CVSS score of 7.6 classifies the flaw as high severity, while an EPSS score of less than 1% indicates a very low probability of exploitation at present. Based on the description, it is inferred that the attacker must have the ability to execute code within the sandboxed context; once inside, an attacker can bypass the isolation to exfiltrate data. The vulnerability is exercised by code running inside the sandbox, so the immediate attacker needs to exploit code execution or supply malicious inputs to run within the sandbox. The flaw is not listed in the CISA KEV catalog, so no public exploit remains known, but the potential impact warrants prompt action.
OpenCVE Enrichment
Github GHSA