CVE-2026-39888Disclosure(praison / praisonai)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch praison praisonai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted __builtins__ dict and an AST-based blocklist. The AST blocklist embedded inside the subprocess wrapper (blocked_attrs of python_tools.py) contains only 11 attribute names — a strict subset of the 30+ names blocked in the direct-execution path. The four attributes that form a frame-traversal chain out of the sandbox are all absent from the subprocess list (__traceback__, tb_frame, f_back, and f_builtins). Chaining these attributes through a caught exception exposes the real Python builtins dict of the subprocess wrapper frame, from which exec can be retrieved and called under a non-blocked variable name — bypassing every remaining security layer. This vulnerability is fixed in 1.5.115.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-657CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-04-08: 2Mentions · 2026-04-09: 3Mentions · 2026-04-15: 1Mentions · 2026-05-26: 1PoC Mentioned / Linked · 2026-05-26: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-15: 1Technical Details · 2026-05-26: 104-0804-0904-1505-26
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure2
2026-04-093
Disclosure2Patch1
2026-04-151
Disclosure1
2026-05-261
Disclosure1
Full discourse7 posts
  • Julio Elizondo@jelizor
    Disclosure

    In May 2026 the concept of a "secure sandbox for AI agents" was demolished seven times in thirty days. vm2, the most widely used JavaScript library for isolating AI-generated code, received three critical CVEs in rapid succession. The most severe, CVE-2026-26956 (CVSS 9.8), exploits WebAssembly exception handling to completely bypass the library's code transformer. A host error object escapes into the sandbox without sanitization, the attacker walks up the constructor chain to the Node.js process object, arbitrary command execution on the host. Public proof of concept. The other two, CVE-2026-43999 (CVSS 9.9) and CVE-2026-45411 (CVSS 9.8), complete the picture. The maintainers declared vm2 officially deprecated and discontinued, stating that architectural limitations make it impossible to keep up with changes to the V8 engine. Not a missed patch. An admission of impossibility. Enclave, the sandbox designed specifically to replace vm2 and offer "safe AI agent code execution", fell to CVE-2026-27597. CVSS 10.0, the maximum possible score. PraisonAI, a multi-agent framework: CVE-2026-39888, CVSS 9.9. The sandbox in subprocess mode blocks 11 attributes. The direct execution path blocks 30. The four attributes needed for frame traversal are absent. n8n, a workflow automation platform used in hundreds of thousands of enterprise instances: CVE-2026-25049, CVSS 9.8. Any authenticated user takes complete control of the server. Credentials, API keys, AI pipelines hijackable. NousResearch hermes-agent: CVE-2026-9368. Sandbox escape via environment variable handler. Public exploit. The vendor never responded to the disclosure. The pattern is the same in every case. Prompt becomes code, code runs in a sandbox, sandbox fails, the attacker is on the host. Seven different products, five languages, same sequence. If you are building autonomous agents that generate and execute code, look at these numbers carefully. The sandbox you are probably relying on either no longer exists or has a CVSS above 9. #TheAgentProblem #AISecurity #Agents

    Post summary

    The post announces multiple recent, high‑CVSS sandbox escape CVEs across several AI agent frameworks, noting that public proof‑of‑concept exploits exist and many maintainers have deprecated affected libraries.

    0000070
    27 followersView on X
  • RB@RynBsd
    Disclosure

    CVE-2026-39888 + CVE-2026-39890: RCE حرج بدرجة 9.9 في منصة PraisonAI متعددة الوكلاء https://t.co/ZEhcbpN0Ep

    Post summary

    The tweet announces two critical RCE vulnerabilities (CVE-2026-39888 and CVE-2026-39890) affecting the multi‑agent PraisonAI platform, with a severity score of 9.9.

    0000031
    8 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PraisonAI Agents, Sandbox Escape, #CVE-2026-39888 (Critical) https://dailycve.com/praisonai-agents-sandbox-escape-cve-2026-39888-critical/

    Post summary

    The tweet announces a critical sandbox escape vulnerability (CVE-2026-39888) and provides a link to a daily CVE article, but offers no further technical, exploit, or mitigation details.

    0000031
    178 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39888: CRITICAL] Prior to version 1.5.115, a security vulnerability in PrasionAI allowed bypassing its security layers by chaining attributes through a caught exception, fixed in the latest release.#cve,CVE-2026-39888,#cybersecurity https://cvefind.com/CVE-2026-39888

    Post summary

    The post announces CVE-2026-39888 in PrasionAI, explains how it bypasses security layers via chaining attributes through an exception, and notes that the latest release includes a fix.

    0000039
    619 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `PraisonAI` is affected by a critical sandbox escape (CVE-2026-39888) via exception frame traversal. This could lead to arbitrary code execution. Monitor vendor advisories for updates. #PraisonAI #Cybersecurity #AppSec https://www.pulsepatch.io/posts/cve-2026-39888-praisonai-sandbox-escape

    Post summary

    A new CVE-2026-39888 constitutes a sandbox escape that may allow arbitrary code execution in PraisAI; users should watch vendor advisories for patches.

    0000051
    11 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39888 PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in http://praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user co… https://www.cve.org/CVERecord?id=CVE-2026-39888 ----- Traducción: CVE-2026-39888 P… http://infoflow.cloud`

    Post summary

    CVE-2026-39888 exposes a sandbox default in earlier PraisonAI versions; no PoC, exploit, or active use reported, and no patch or workaround is mentioned.

    0000026
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39888 PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in http://praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user co… https://www.cve.org/CVERecord?id=CVE-2026-39888

    Post summary

    CVE-2026-39888 highlights a default configuration issue in PraisonAI’s execute_code() function that could permit unintended code execution; no PoC, exploit, or patch is provided.

    00000186
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more