Impact
PraisonAI before version 4.6.78 suffers from an unenforced security policy in its default Subprocess Sandbox backend. The configuration options blocked_commands, blocked_paths, blocked_imports, allow_subprocess, and allow_file_write are completely ignored, enabling an attacker to execute arbitrary subprocess commands, read any file accessible to the process, and perform destructive operations. This flaw is classified as CWE‑273, indicating a direct bypass of intended sandbox restrictions.
Affected Systems
The affected vendor is MervinPraison and the product is PraisonAI. Versions earlier than 4.6.78 are vulnerable, as the sandbox policy constraints are not enforced in those releases. Systems running any of those earlier releases are susceptible to exploitation through the Subprocess Sandbox.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity vulnerability, though the EPSS score of <1% signals a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation has been reported. The likely attack vector is an application or environment that processes untrusted input or otherwise allows controlled interaction with the sandbox, whereby an attacker can trigger privileged subprocess execution or file access.
OpenCVE Enrichment