Junglewise Threat Intelligence

CVE-2026-34938: MervinPraison PraisonAI sandbox escape in execute_code

CVE-2026-34938 · Severity: critical · CVSS 10 · Published 2026-04-03

Technologies: praisonaiagents (PyPI), Praisonaiagents. Vendors: PyPI, Praison, MervinPraison.

Executive brief

PraisonAI is a framework for managing teams of AI agents. A security flaw in its code execution component allows an attacker to bypass built-in safety restrictions and run unauthorized commands on the underlying server. This could lead to a total system takeover, theft of sensitive data, or disruption of operations, especially in deployments where AI agents are configured to run tasks automatically without human approval.

Technical details

A sandbox escape vulnerability exists in the 'execute_code' function of the praisonai-agents package. The vulnerability stems from a logic error in the '_safe_getattr' wrapper, which attempts to block access to sensitive attributes (those starting with underscores) using 'name.startswith('_')'. Because the wrapper accepts any 'str' subclass, an attacker can provide a custom string object with a malicious 'startswith' method that always returns 'False', bypassing the security check. By leveraging 'type()' (which is permitted in the sandbox) to create this subclass, an attacker can access '__subclasses__' and other internal attributes to reach the 'subprocess.Popen' class. This allows for arbitrary OS command execution with the privileges of the application process. The issue is particularly severe in 'autonomy_mode' where 'PRAISONAI_AUTO_APPROVE' is enabled by default. The vulnerability is patched in version 1.5.90.

Affected products

  • MervinPraison PraisonAI (praisonai-agents) < 1.5.90

Timeline

  • 2026-03-31: advisory: Vendor advisory published on GitHub
  • 2026-04-03: disclosed: CVE published to NVD
  • 2026-04-03: patched: Fix released in version 1.5.90

References

Related threats