Sandbox Mode Bypass in PraisonAI Affects Multi-Agent Teams System
CVE-2026-57120

6.5MEDIUM

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-57120?

The PraisonAI platform prior to version 1.6.59 has a vulnerability where the execute_code sandbox mode allows for the runtime assembly of blocked names. This permits code to access C-level attributes, thus bypassing the intended _safe_getattr safeguards. Consequently, attributes integral to classes, such as qualified names and globals, may be exploited by prompt-influenced code, facilitating access to sensitive information without a complete execution chain inside the process.

Affected Version(s)

praisonaiagents < 1.6.59

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.