CVE-2026-57138
9.9MervinPraison · PraisonAI
PraisonAI versions 1.4.0 through 1.7.1 contain a sandbox escape vulnerability in the codeMode tool, allowing authenticated attackers to execute arbitrary code on the host filesystem.
Executive summary
A critical sandbox escape vulnerability in MervinPraison PraisonAI allows authenticated attackers to execute arbitrary code, potentially leading to a full host system compromise.
Vulnerability
The vulnerability stems from an insecure implementation of the codeMode tool, which utilizes an inadequate sandbox mechanism to execute untrusted JavaScript. By leveraging constructor manipulation, an authenticated attacker can bypass the sandbox to access sensitive host filesystem APIs and execute arbitrary subprocesses.
Business impact
The exploitation of this vulnerability poses a severe risk to organizational infrastructure, as it grants attackers the ability to read sensitive secrets, modify critical files, and execute arbitrary commands on the underlying host. Given the CVSS score of 9.9, this flaw represents an extreme risk to confidentiality, integrity, and availability, potentially facilitating lateral movement within the network or complete system takeover.
Remediation
Immediate Action: Upgrade to PraisonAI version 1.7.2 or later immediately to apply the necessary security patches and sandbox improvements.
Proactive Monitoring: Review application logs for suspicious input patterns directed at the codeMode module and monitor host processes for unexpected subprocess execution or unauthorized file access.
Compensating Controls: If immediate patching is not feasible, restrict access to the PraisonAI interface to trusted users only and implement strict network-level egress filtering to prevent the application from reaching out to malicious command and control servers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates an immediate response. Organizations utilizing PraisonAI must prioritize the update to version 1.7.2, as the current sandbox implementation is fundamentally flawed and cannot be fully secured without the provided vendor patch. Failure to update leaves systems exposed to complete compromise by any authenticated user.
More MervinPraison CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section