Network Isolation Vulnerability in PraisonAI by Mervin Praison
CVE-2026-57135

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-57135?

In PraisonAI, the SandboxExecutor's network-isolated mode contains a vulnerability due to improper handling of HTTP proxy environment variables. From versions 1.2.3 to 1.7.2, this flaw allows commands that should be isolated to bypass network boundaries, potentially exposing internal services or enabling data exfiltration. Programs that overlook these proxy settings can directly access localhost or external hosts. An initial remediation has been made available in version 1.7.2.

Affected Version(s)

PraisonAI >= 1.2.3, < 1.7.2

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.