Executive brief
PraisonAI is a framework for managing multi-agent AI systems. A security flaw in its code execution tool allows an attacker or a malicious AI agent to break out of the restricted "sandbox" environment. This could lead to full control over the underlying server, allowing unauthorized access to sensitive files, API keys, and internal networks.
Technical details
The vulnerability exists in the `execute_code` function within `praisonaiagents.tools.python_tools`. When running in the default `sandbox_mode="sandbox"`, the system uses an AST-based blocklist to prevent access to dangerous Python attributes. However, the blocklist used in subprocess mode is significantly weaker than the one used in direct mode, omitting critical attributes such as `__traceback__`, `tb_frame`, `f_back`, and `f_builtins`. An attacker can chain these attributes through a caught exception to traverse the call stack, access the real Python builtins dictionary of the wrapper frame, and retrieve the `exec` function. This allows for arbitrary code execution on the host system, bypassing all intended sandbox restrictions. The issue is fixed in version 1.5.115 by synchronizing the blocklists.
Affected products
- MervinPraison (PraisonAI) praisonaiagents < 1.5.115
Timeline
- 2026-04-07: advisory: Vendor advisory published on GitHub
- 2026-04-08: disclosed: CVE published to NVD