Network Isolation Vulnerability in PraisonAI by Mervin Praison
CVE-2026-57135
7.6HIGH
What is CVE-2026-57135?
In PraisonAI, the SandboxExecutor's network-isolated mode contains a vulnerability due to improper handling of HTTP proxy environment variables. From versions 1.2.3 to 1.7.2, this flaw allows commands that should be isolated to bypass network boundaries, potentially exposing internal services or enabling data exfiltration. Programs that overlook these proxy settings can directly access localhost or external hosts. An initial remediation has been made available in version 1.7.2.
Affected Version(s)
PraisonAI >= 1.2.3, < 1.7.2
