
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39888 is a critical sandbox escape vulnerability in PraisonAI's execute_code() function within the praisonaiagents.tools.python_tools module. It allows low-privileged, network-accessible attackers to escape the Python subprocess sandbox and execute arbitrary code on the host system. All versions of the praisonaiagents PyPI package up to and including 1.5.114 are affected; the issue was fixed in version 1.5.115. The vulnerability was published on April 8, 2026, with a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, PraisonAI Advisory).
The root cause is a violation of secure design principles (CWE-657) and protection mechanism failure (CWE-693): the execute_code() function maintains two separate blocked_attrs sets — one used in direct-execution mode (30+ attributes) and a weaker inline set used in subprocess/sandbox mode (only 11 attributes). The subprocess blocklist omits four critical frame-traversal attributes: __traceback__, tb_frame, f_back, and f_builtins. An attacker can chain these attributes through a caught exception to traverse Python call frames and access the real __builtins__ dictionary of the subprocess wrapper, from which exec can be retrieved under an alias variable name, bypassing the AST check entirely. Additionally, _safe_getattr only intercepts explicit getattr() calls and not direct dot-notation attribute access (which uses Python's C-level tp_getattro), and the subprocess mode lacks the text-pattern dangerous_patterns blocklist present in direct mode — leaving the AST check as the sole (and insufficient) barrier (GitHub Advisory, PraisonAI Advisory).
Successful exploitation grants an attacker arbitrary code execution on the host system with the privileges of the PraisonAI application process, fully escaping the intended subprocess sandbox. The scope change (S:C) means the impact extends beyond the sandboxed component to the entire host: attackers can read arbitrary files (source code, .env files, SSH keys, API keys), write or modify files, exfiltrate environment variables, establish outbound network connections to attacker infrastructure, and perform lateral movement since the subprocess inherits the host's full network stack and filesystem. All three security pillars — confidentiality, integrity, and availability — are rated High (GitHub Advisory, PraisonAI Advisory).
A public proof-of-concept (PoC) is included in the GitHub Security Advisory itself, demonstrating full RCE in a single API call on praisonaiagents 1.5.113 with Python 3.10. As of the time of reporting, there is no evidence of active in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.042% (0.00084 per Feedly), placing it in the 13th percentile for near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only low privileges (the ability to submit code through a PraisonAI agent) and no user interaction, making it accessible to any authenticated end user or LLM-generated input in standard deployments (GitHub Advisory, PraisonAI Advisory).
execute_code() agent tool to user-controlled or LLM-generated input, accessible over the network.try:
1/0
except ZeroDivisionError as e:
_p = e.__traceback__.tb_frame.f_back
_x = _p.f_builtins["exec"]
_x("import subprocess; print(subprocess.check_output('id', shell=True).decode())", {"__builtins__": _p.f_builtins})execute_code(): Pass the crafted code to execute_code(code=payload) (e.g., through the agent API or by setting PRAISONAI_AUTO_APPROVE=true in automated contexts). The AST blocklist does not flag __traceback__, tb_frame, f_back, or f_builtins, so the code passes validation.__builtins__ dict; exec is retrieved under the alias _x (bypassing the exec-by-name AST check) and used to run arbitrary shell commands on the host, returning output such as uid=1000(user) gid=1000(user) groups=1000(user)..env files or SSH keys, or pivot laterally using the host's network stack (GitHub Advisory, PraisonAI Advisory).execute_code() with payloads containing __traceback__, tb_frame, f_back, or f_builtins attribute access patterns; unexpected ZeroDivisionError or similar exception traces in PraisonAI logs originating from user-submitted code./bin/sh, /bin/bash, subprocess, curl, wget, python) executing system commands like id, whoami, or network utilities..env files); access or modification timestamps on sensitive files (SSH keys, .env, credential stores) coinciding with agent activity.The primary remediation is to upgrade the praisonaiagents PyPI package to version 1.5.115 or later, which merges the subprocess blocked_attrs with the full direct-mode blocklist and adds additional AST-level protections. If immediate patching is not possible, restrict access to the execute_code() function to only fully trusted users, or disable the feature entirely. As a network-level control, limit exposure of PraisonAI agent endpoints to authenticated and authorized users only, and monitor for suspicious code execution patterns. The advisory also recommends adding a blanket AST rule to block any attribute access starting with _ and mirroring the dangerous_patterns text-pattern check in subprocess mode as defense-in-depth (GitHub Advisory, PraisonAI Advisory).
The vulnerability received coverage from The Hacker Wire, which published a dedicated technical write-up on the AST sandbox bypass leading to RCE, as well as a broader article on PraisonAI security issues (The Hacker Wire). The issue was also noted alongside a related template injection vulnerability (CVE-2026-39891) and a dual critical RCE report covering CVE-2026-39888 and CVE-2026-39890, indicating a cluster of security findings in PraisonAI around the same disclosure period. Social media discussion was observed on Mastodon and Nitter, though no major threat actor commentary or widespread community alarm has been documented.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."