Impact
PraisonAI’s codeMode feature runs untrusted JavaScript inside a sandbox that relies on a small source‑code blocklist and shadowing of process and require values. The vulnerability allows an attacker to recover the underlying Function constructor via ({}).constructor.constructor, access the host’s process and require objects, and then read sensitive data, modify files, execute arbitrary commands or exhaust system resources. The weakness is a form of improper control of code execution and insecure use of Function, resulting in a high‑severity compromise of confidentiality, integrity, and availability.
Affected Systems
The issue affects the MervinPraison:PraisonAI product, specifically all releases from 1.4.0 through 1.7.2. Versions 1.7.2 and later incorporate the fix.
Risk and Exploitability
The CVSS score of 9.9 indicates the most severe risk level, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but possible. The vulnerability is not yet listed in the CISA KEV catalog. An exploit requires an attacker to supply malicious code to the codeMode input; the likely vector is a local user or an attacker who can influence the input, such as through compromised plugins or remote code injection into the environment that uses codeMode.
OpenCVE Enrichment
Github GHSA