Description
PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use ({}).constructor.constructor to recover the real Function constructor, obtain process and process.mainModule.require, and reach host filesystem and subprocess APIs despite the advertised sandbox. Attackers who control codeMode input can read secrets, modify files, execute commands, or exhaust the host process. This issue is fixed in version 1.7.2.
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

PraisonAI’s codeMode feature runs untrusted JavaScript inside a sandbox that relies on a small source‑code blocklist and shadowing of process and require values. The vulnerability allows an attacker to recover the underlying Function constructor via ({}).constructor.constructor, access the host’s process and require objects, and then read sensitive data, modify files, execute arbitrary commands or exhaust system resources. The weakness is a form of improper control of code execution and insecure use of Function, resulting in a high‑severity compromise of confidentiality, integrity, and availability.

Affected Systems

The issue affects the MervinPraison:PraisonAI product, specifically all releases from 1.4.0 through 1.7.2. Versions 1.7.2 and later incorporate the fix.

Risk and Exploitability

The CVSS score of 9.9 indicates the most severe risk level, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but possible. The vulnerability is not yet listed in the CISA KEV catalog. An exploit requires an attacker to supply malicious code to the codeMode input; the likely vector is a local user or an attacker who can influence the input, such as through compromised plugins or remote code injection into the environment that uses codeMode.

Generated by OpenCVE AI on September 17, 2026 at 17:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch by upgrading to PraisonAI version 1.7.2 or later, which resolves the CWE‑184 flaw of improper control of code execution.
  • If upgrading is not immediately possible, sanitize or whitelist the codeMode input strictly to block patterns that allow recreation of the Function constructor, addressing both CWE‑184 and CWE‑693 protection misconfiguration.
  • Modify the sandbox configuration to remove shadowed process and require objects, ensuring that no host filesystem access is possible, as recommended for mitigating CWE‑693.
  • If neither patching nor sanitization can be applied promptly, disable the codeMode feature or remove the vulnerable source‑code block until a fix becomes available.

Generated by OpenCVE AI on September 17, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vmmj-pfw7-fjwp npm PraisonAI codeMode sandbox escape via Function constructor
History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use ({}).constructor.constructor to recover the real Function constructor, obtain process and process.mainModule.require, and reach host filesystem and subprocess APIs despite the advertised sandbox. Attackers who control codeMode input can read secrets, modify files, execute commands, or exhaust the host process. This issue is fixed in version 1.7.2.
Title PraisonAI codeMode sandbox escape via Function constructor
Weaknesses CWE-184
CWE-693
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:13:25.541Z

Reserved: 2026-06-24T01:45:48.696Z

Link: CVE-2026-57138

cve-icon Vulnrichment

Updated: 2026-09-17T14:13:20.451Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:11.180

Modified: 2026-09-17T14:17:14.627

Link: CVE-2026-57138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs

  • CWE-693

    Protection Mechanism Failure