Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pv2j-rghr-v5r9 | PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr. This exposes class, qualified-name, base-class, globals, and object-dictionary attributes to prompt-influenced code when approval is automatically granted, producing a high-impact read primitive without establishing a complete in-process execution chain. This issue is fixed in praisonaiagents 1.6.59. | |
| Title | PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T14:48:14.932Z
Reserved: 2026-06-24T00:33:17.707Z
Link: CVE-2026-57120
No data.
Status : Received
Published: 2026-09-14T15:17:05.607
Modified: 2026-09-14T15:17:05.607
Link: CVE-2026-57120
No data.
OpenCVE Enrichment
No data.
Github GHSA