CVE-2026-34938Disclosure(praison / praisonaiagents)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch praison praisonaiagents systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitrary OS command execution on the host. This issue has been patched in version 1.5.90.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonaiagents

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-04); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
praisonaiagents

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 2Mentions · 2026-04-06: 1Mentions · 2026-08-08: 1PoC Mentioned / Linked · 2026-04-04: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 2Technical Details · 2026-04-06: 104-0204-0304-0404-0608-08
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-031
Patch1
2026-04-042
Disclosure2
2026-04-061
Disclosure1
2026-08-081
General1
Full discourse6 posts
  • maruomosquit@maru1151157
    Disclosure

    🚨 CVE-2026-34938 (CVSS: 10.0) PraisonAI 1.5.90以前では、_safe_getattrにstrサブクラス(startswithオーバーライド)を渡すことで3層サンドボックスをバイパスし、任意OSコマンド実行可能。バージョン1.5.90で修正。 https://maruomosquit.com/vulnerability/CVE-2026-34938/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-34938 is a critical sandbox bypass in PraisAI that allows arbitrary OS command execution; the issue is fixed in version 1.5.90, and a reference link is provided.

    0002039
    1.3K followersView on X
  • S.Komichevsen Matsuk@w4yh
    Disclosure

    わお // PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code · CVE-2026-34938 · GitHub Advisory Database https://github.com/advisories/GHSA-6vh2-h83c-9294

    Post summary

    The advisory announces a new PraisonAI vulnerability (CVE-2026-34938) that allows Python sandbox escape via a str subclass startswith() override.

    0001067
    321 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34938: CRITICAL] PraisonAI patched a critical issue in version 1.5.90 where attacker-controlled Python code could bypass the sandbox, allowing arbitrary OS command execution on the host.#cve,CVE-2026-34938,#cybersecurity https://cvefind.com/CVE-2026-34938

    Post summary

    The tweet reports that PraisionAI has released a patch for CVE-2026-34938, a critical vulnerability allowing arbitrary OS command execution via sandbox bypass.

    0001057
    619 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-34938: PraisonAI Sandbox Escape Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04slbxm0

    Post summary

    The provided text is a headline and URL offering no substantive details about the CVE, indicating a generic reference to a blog post on PraisonAI sandbox escape but lacking specific indicators.

    0000041
    32 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34938 - Critical PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypasse... https://www.thehackerwire.com/vulnerability/CVE-2026-34938/ https://t.co/aTm2EBSty9

    Post summary

    The tweet discloses a critical vulnerability (CVE-2026-34938) wherein the execute_code() function in PraisonAI allows attacker-controlled Python to bypass a three-layer sandbox. While it provides technical details and a link to further information, it does not mention a PoC, exploit tool, active exploitation, or patch.

    0000051
    164 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    PraisonAI is affected by a critical Python sandbox escape vulnerability (CVE-2026-34938). This flaw allows execution outside the sandbox. Monitor for fixes. #Python #SandboxEscape #Infosec https://www.pulsepatch.io/posts/cve-2026-34938-praisonai-python-sandbox-escape

    Post summary

    A critical Python sandbox escape vulnerability (CVE-2026-34938) affecting PraisionAI is announced, permitting execution outside the sandbox; no PoC, exploit, or patch details are provided, and users are urged to monitor for fixes.

    0000030
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonaiagents---

Explore more