Executive brief
PraisonAI is an AI agent framework that includes a sandbox for safely running untrusted code. A vulnerability exists where the sandbox fails to enforce security restrictions if the underlying Linux security module (Landlock) is unavailable. In such cases, the system silently falls back to an unrestricted execution mode, allowing untrusted code to read sensitive files, access the network, and potentially compromise the host system.
Technical details
The `praisonai.sandbox.SandlockSandbox` component is designed to provide kernel-enforced isolation using Landlock. However, the `execute()` and `run_command()` methods contain a fail-open logic flaw: if the `sandlock` module reports that Landlock is unavailable (e.g., on incompatible kernels or non-Linux systems), the sandbox silently falls back to `SubprocessSandbox`. This fallback does not implement the configured `SecurityPolicy` restrictions for filesystem paths or network access. An attacker providing code to be executed in what is ostensibly a 'native' sandbox can bypass all intended boundaries to read arbitrary files or establish network connections. The issue was addressed in version 4.6.61 by ensuring the sandbox fails closed or requires explicit opt-in for degraded modes.
Affected products
- MervinPraison praisonai >= 4.5.110, < 4.6.61
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-18: patched: Fixed in version 4.6.61