CVE-2026-57135
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly isolated commands to reach localhost, internal services, cloud metadata, or external hosts and potentially exfiltrate data. An initial remediation was released in version 1.7.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
- EPSS probability
- 0.31%
- CWE
- CWE-653, CWE-693
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- MervinPraison PraisonAI
Weakness type
Related vulnerabilities
- CVE-2025-1974 — ingress-nginx admission controller RCE escalation
- CVE-2025-21590 — Junos OS: An local attacker with shell access can execute arbitrary code
- CVE-2026-0542 — Remote Code Execution in ServiceNow AI Platform
- CVE-2025-34201 — Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instances
- CVE-2026-63071 — Apache Syncope: RCE via Groovy Sandbox bypass
- CVE-2026-53421 — Apache Syncope: Remote Code Execution via Scripted Connector
- CVE-2026-53405 — Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
- CVE-2025-12805 — Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy