Junglewise Threat Intelligence

CVE-2026-57120: PraisonAI execute_code sandbox bypass via string format injection

CVE-2026-57120 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: praisonaiagents (PyPI). Vendors: PyPI, PraisonAI.

Executive brief

PraisonAI is a multi-agent AI system that allows controlled code execution within a sandbox. Prior to version 1.6.59, the sandbox's security controls could be bypassed using Python string formatting methods to access restricted internal attributes, allowing an attacker to read sensitive class metadata and globals without full code execution. This affects organizations using PraisonAI to run agent-based workflows with automatically approved code execution.

Technical details

The vulnerability is an attribute-access bypass in the execute_code sandbox that occurs when str.format or str.format_map methods resolve dotted field names. These methods use C-level attribute access that circumvents the _safe_getattr filter intended to block dunder attributes. An attacker can craft prompt-influenced strings that, when formatted, expose __class__, __qualname__, __bases__, __globals__, and __dict__ attributes. No authentication bypass or full in-process code execution is required; the attack succeeds when code approval is automatically granted. The fix in version 1.6.59 hardens input validation and access controls to prevent this attribute resolution path.

Affected products

  • PraisonAI praisonaiagents prior to 1.6.59

Timeline

  • 2026-09-14: disclosed
  • 2026-06-13: patched: Fix committed in version 1.6.59

References

Related threats