Sandbox Mode Bypass in PraisonAI Affects Multi-Agent Teams System
CVE-2026-57120
6.5MEDIUM
What is CVE-2026-57120?
The PraisonAI platform prior to version 1.6.59 has a vulnerability where the execute_code sandbox mode allows for the runtime assembly of blocked names. This permits code to access C-level attributes, thus bypassing the intended _safe_getattr safeguards. Consequently, attributes integral to classes, such as qualified names and globals, may be exploited by prompt-influenced code, facilitating access to sensitive information without a complete execution chain inside the process.
Affected Version(s)
praisonaiagents < 1.6.59
