
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34938 is a critical Python sandbox escape vulnerability in the praisonai-agents package (PraisonAI multi-agent framework) that allows unauthenticated remote attackers to execute arbitrary OS commands on the host system. The flaw resides in the execute_code() function's three-layer sandbox, which can be fully bypassed by supplying a str subclass with an overridden startswith() method to the _safe_getattr wrapper. All versions of praisonaiagents up to and including 1.5.89 are affected; version 1.5.90 contains the fix. The vulnerability was published on March 31, 2026, and assigned a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, PraisonAI Advisory).
The root cause is a Protection Mechanism Failure (CWE-693): the _safe_getattr guard in python_tools.py checks isinstance(name, str) and name.startswith('_') to block access to dunder attributes, but isinstance() returns True for any str subclass, allowing an attacker to pass a FakeStr object whose startswith() always returns False. Because type() is whitelisted in safe_builtins, an attacker can create this subclass without using the class keyword, then use it to construct dunder attribute names (e.g., __mro__, __subclasses__) that bypass the guard. From there, the attacker walks the MRO subclass chain to locate subprocess.Popen and invoke arbitrary OS commands — all from within attacker-controlled Python code passed to execute_code(). The attack requires no authentication, no privileges, and no user interaction, and is exploitable over the network (GitHub Advisory, PraisonAI Advisory).
Successful exploitation grants an attacker full OS command execution with the privileges of the praisonai-agents process, resulting in complete compromise of confidentiality, integrity, and availability on the host. Deployments using bot.py, autonomy_mode.py, or bots_cli.py are particularly at risk because PRAISONAI_AUTO_APPROVE=true is set by default, meaning the malicious tool call fires silently without human confirmation — enabling exploitation via indirect prompt injection with no user interaction. An attacker can exfiltrate sensitive data, install persistent backdoors, pivot to adjacent systems, or disrupt service availability entirely (PraisonAI Advisory, GitHub Advisory).
A fully functional proof-of-concept (PoC) exploit written in Python is publicly available in the GitHub Security Advisory, demonstrating arbitrary OS command execution via subprocess.Popen (PraisonAI Advisory). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.069% (21st percentile), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog at this time. The reporter credited is YeranG30 (GitHub Advisory).
praisonai-agents version ≤ 1.5.89, particularly those running bot.py, autonomy_mode.py, or bots_cli.py with PRAISONAI_AUTO_APPROVE=true.type() builtin to create a str subclass (FakeStr) with startswith overridden to always return False:t = type
FakeStr = t('FakeStr', (str,), {'startswith': lambda self, *a: False})FakeStr instances to construct dunder attribute strings (e.g., __mro__, __subclasses__, __module__, __name__) that bypass the _safe_getattr guard, since FakeStr('__mro__').startswith('_') returns False.getattr with the crafted FakeStr names to access object.__subclasses__() and iterate over all loaded classes to find subprocess.Popen:obj_class = getattr(type(()), mro_attr)[1]
for cls in getattr(obj_class, subs_attr)():
if getattr(cls, mod_attr, '') == 'subprocess' and getattr(cls, name_attr, '') == 'Popen':
# Found PopenPopen with the desired command and retrieve output:r = cls(['id'], stdout=PIPE, stderr=PIPE)
out, err = r.communicate()
print('RCE:', out.decode())execute_code() is triggered automatically without human review (PraisonAI Advisory, GitHub Advisory).praisonai-agents Python process, such as id, whoami, bash, sh, curl, wget, or other OS utilities not normally invoked by the application.execute_code() invocations with payloads containing strings like FakeStr, startswith, __subclasses__, subprocess, or Popen; Python tracebacks or RCE: output strings in stdout/stderr logs.praisonai-agents to external IPs, particularly following agent task execution; reverse shell connections on non-standard ports.praisonai-agents process, including web shells, cron jobs, SSH authorized keys, or downloaded binaries created by the process user.PRAISONAI_AUTO_APPROVE=true in the process environment combined with externally supplied agent inputs, indicating silent auto-execution risk (PraisonAI Advisory).The vendor has released a patch in praisonaiagents version 1.5.90; all users should upgrade immediately via pip install --upgrade praisonaiagents (GitHub Advisory). If immediate patching is not possible, restrict network access to systems running praisonai-agents and avoid exposing the execute_code() functionality to untrusted inputs. Additionally, disable or override the PRAISONAI_AUTO_APPROVE=true default in bot.py, autonomy_mode.py, and bots_cli.py to require human confirmation before tool execution, reducing the risk of silent exploitation via prompt injection (PraisonAI Advisory).
The vulnerability received notable community attention shortly after disclosure, with posts on Mastodon and Bluesky highlighting the sandbox escape technique and its implications for AI agent frameworks (Mastodon/@thehackerwire). A dev.to article titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" contextualized this vulnerability alongside other PraisonAI security issues discovered in the same period, drawing broader attention to security weaknesses in AI agent frameworks. Security researchers at Yazoul published a dedicated advisory analyzing the RCE impact, and The Hacker Wire covered related PraisonAI vulnerabilities including an SSRF issue in the same disclosure cycle (Yazoul Advisory, The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."