Junglewise Threat Intelligence

CVE-2026-39888: PraisonAI sandbox escape via frame traversal in execute_code

CVE-2026-39888 · Severity: critical · CVSS 9.9 · Published 2026-04-08

Technologies: praisonaiagents (PyPI), MervinPraison PraisonAI Agents, Praisonai, MervinPraison (PraisonAI) Praisonaiagents. Vendors: PyPI, MervinPraison, Praison.

Executive brief

PraisonAI is a framework for managing multi-agent AI systems. A security flaw in its code execution tool allows an attacker or a malicious AI agent to break out of the restricted "sandbox" environment. This could lead to full control over the underlying server, allowing unauthorized access to sensitive files, API keys, and internal networks.

Technical details

The vulnerability exists in the `execute_code` function within `praisonaiagents.tools.python_tools`. When running in the default `sandbox_mode="sandbox"`, the system uses an AST-based blocklist to prevent access to dangerous Python attributes. However, the blocklist used in subprocess mode is significantly weaker than the one used in direct mode, omitting critical attributes such as `__traceback__`, `tb_frame`, `f_back`, and `f_builtins`. An attacker can chain these attributes through a caught exception to traverse the call stack, access the real Python builtins dictionary of the wrapper frame, and retrieve the `exec` function. This allows for arbitrary code execution on the host system, bypassing all intended sandbox restrictions. The issue is fixed in version 1.5.115 by synchronizing the blocklists.

Affected products

  • MervinPraison (PraisonAI) praisonaiagents < 1.5.115

Timeline

  • 2026-04-07: advisory: Vendor advisory published on GitHub
  • 2026-04-08: disclosed: CVE published to NVD

References

Related threats