CVE-2026-39888: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-39888 is a critical sandbox escape vulnerability in PraisonAI's execute_code() function within the praisonaiagents.tools.python_tools module. It allows low-privileged, network-accessible attackers to escape the Python subprocess sandbox and execute arbitrary code on the host system. All versions of the praisonaiagents PyPI package up to and including 1.5.114 are affected; the issue was fixed in version 1.5.115. The vulnerability was published on April 8, 2026, with a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, PraisonAI Advisory).

Technical details

The root cause is a violation of secure design principles (CWE-657) and protection mechanism failure (CWE-693): the execute_code() function maintains two separate blocked_attrs sets — one used in direct-execution mode (30+ attributes) and a weaker inline set used in subprocess/sandbox mode (only 11 attributes). The subprocess blocklist omits four critical frame-traversal attributes: __traceback__, tb_frame, f_back, and f_builtins. An attacker can chain these attributes through a caught exception to traverse Python call frames and access the real __builtins__ dictionary of the subprocess wrapper, from which exec can be retrieved under an alias variable name, bypassing the AST check entirely. Additionally, _safe_getattr only intercepts explicit getattr() calls and not direct dot-notation attribute access (which uses Python's C-level tp_getattro), and the subprocess mode lacks the text-pattern dangerous_patterns blocklist present in direct mode — leaving the AST check as the sole (and insufficient) barrier (GitHub Advisory, PraisonAI Advisory).

Impact

Successful exploitation grants an attacker arbitrary code execution on the host system with the privileges of the PraisonAI application process, fully escaping the intended subprocess sandbox. The scope change (S:C) means the impact extends beyond the sandboxed component to the entire host: attackers can read arbitrary files (source code, .env files, SSH keys, API keys), write or modify files, exfiltrate environment variables, establish outbound network connections to attacker infrastructure, and perform lateral movement since the subprocess inherits the host's full network stack and filesystem. All three security pillars — confidentiality, integrity, and availability — are rated High (GitHub Advisory, PraisonAI Advisory).

Exploitability

A public proof-of-concept (PoC) is included in the GitHub Security Advisory itself, demonstrating full RCE in a single API call on praisonaiagents 1.5.113 with Python 3.10. As of the time of reporting, there is no evidence of active in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.042% (0.00084 per Feedly), placing it in the 13th percentile for near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only low privileges (the ability to submit code through a PraisonAI agent) and no user interaction, making it accessible to any authenticated end user or LLM-generated input in standard deployments (GitHub Advisory, PraisonAI Advisory).

Exploitation steps

  1. Identify target: Locate a PraisonAI deployment (version ≤ 1.5.114) that exposes the execute_code() agent tool to user-controlled or LLM-generated input, accessible over the network.
  2. Obtain low-privileged access: Authenticate to the PraisonAI instance with any standard end-user account sufficient to submit code through an agent.
  3. Craft the sandbox escape payload: Construct a Python snippet that deliberately raises an exception, then traverses the call frame chain via the unblocked attributes:
try:
    1/0
except ZeroDivisionError as e:
    _p = e.__traceback__.tb_frame.f_back
    _x = _p.f_builtins["exec"]
    _x("import subprocess; print(subprocess.check_output('id', shell=True).decode())", {"__builtins__": _p.f_builtins})
  1. Submit payload via execute_code(): Pass the crafted code to execute_code(code=payload) (e.g., through the agent API or by setting PRAISONAI_AUTO_APPROVE=true in automated contexts). The AST blocklist does not flag __traceback__, tb_frame, f_back, or f_builtins, so the code passes validation.
  2. Achieve RCE: The frame traversal exposes the real __builtins__ dict; exec is retrieved under the alias _x (bypassing the exec-by-name AST check) and used to run arbitrary shell commands on the host, returning output such as uid=1000(user) gid=1000(user) groups=1000(user).
  3. Post-exploitation: Use the established code execution to exfiltrate credentials, establish a reverse shell, read .env files or SSH keys, or pivot laterally using the host's network stack (GitHub Advisory, PraisonAI Advisory).

Indicators of compromise

  • Logs: Application logs showing calls to execute_code() with payloads containing __traceback__, tb_frame, f_back, or f_builtins attribute access patterns; unexpected ZeroDivisionError or similar exception traces in PraisonAI logs originating from user-submitted code.
  • Process: Unusual child processes spawned by the PraisonAI Python process (e.g., /bin/sh, /bin/bash, subprocess, curl, wget, python) executing system commands like id, whoami, or network utilities.
  • File System: Unexpected new files written to the PraisonAI working directory or temp directories (e.g., web shells, exfiltration scripts, modified .env files); access or modification timestamps on sensitive files (SSH keys, .env, credential stores) coinciding with agent activity.
  • Network: Unexpected outbound connections from the PraisonAI host process to external IPs or domains not associated with normal LLM API endpoints; unusual DNS lookups or data exfiltration traffic originating from the application process.
  • Environment: Evidence of environment variable reads (e.g., API keys, secrets) by the agent subprocess beyond expected scope (GitHub Advisory, PraisonAI Advisory).

Mitigation and workarounds

The primary remediation is to upgrade the praisonaiagents PyPI package to version 1.5.115 or later, which merges the subprocess blocked_attrs with the full direct-mode blocklist and adds additional AST-level protections. If immediate patching is not possible, restrict access to the execute_code() function to only fully trusted users, or disable the feature entirely. As a network-level control, limit exposure of PraisonAI agent endpoints to authenticated and authorized users only, and monitor for suspicious code execution patterns. The advisory also recommends adding a blanket AST rule to block any attribute access starting with _ and mirroring the dangerous_patterns text-pattern check in subprocess mode as defense-in-depth (GitHub Advisory, PraisonAI Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published a dedicated technical write-up on the AST sandbox bypass leading to RCE, as well as a broader article on PraisonAI security issues (The Hacker Wire). The issue was also noted alongside a related template injection vulnerability (CVE-2026-39891) and a dual critical RCE report covering CVE-2026-39888 and CVE-2026-39890, indicating a cluster of security findings in PraisonAI around the same disclosure period. Social media discussion was observed on Mastodon and Nitter, though no major threat actor commentary or widespread community alarm has been documented.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management