Impact
The codeMode tool in PraisonAI, before version 1.7.2, evaluated JavaScript supplied by a language model using new Function() in combination with the with(sandbox) syntax. A crafted regular expression bypass allows an attacker to execute Function('return this')() in order to recover the global object and to dynamically construct the child_process module name. If the attacker can influence the code argument, they can gain the PraisonAI process’s privileges, read or write arbitrary files, access environment credentials, and execute operating‑system commands. This critical code injection and sandbox escape flaw is mitigated in version 1.7.2.
Affected Systems
All versions of MervinPraison’s PraisonAI prior to 1.7.2 are vulnerable, including releases bundled in the v4.6.60 package and earlier. The issue is fixed in version 1.7.2 and subsequent releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating a critical impact level. The EPSS score of less than 1% suggests that exploitation has not yet been widely observed, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to supply tainted code to the codeMode tool, which, if not adequately protected, leads to remote code execution with full process privileges.
OpenCVE Enrichment
Github GHSA