Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-57138: PraiserAI 1.4‑0 to 1.7‑2 codeMode lets attackers access host
CVE-2026-57138 · published 13 days ago
Summary
Versions 1.4.0 through 1.7.1 of PraiserAI run user‑supplied JavaScript in a sandbox that can be broken. An attacker can escape the sandbox, read files, change data, or run commands on the server. Upgrade to version 1.7.2 or later to close the escape route.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mervinpraison | praisonai | >= 1.4.0, < 1.7.2 |
Original advisory text
PraisonAI codeMode sandbox escape via Function constructor
PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use ({}).constructor.constructor to recover the real Function constructor, obtain process and process.mainModule.require, and reach host filesystem and subprocess APIs despite the advertised sandbox. Attackers who control codeMode input can read secrets, modify files, execute commands, or exhaust the host process. This issue is fixed in version 1.7.2.
Severity
9.9
Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-184Incomplete List of Disallowed Inputs
CWE-693Protection Mechanism Failure
Timeline
Published15 Sep 2026
Updated27 Sep 2026
First seen15 Sep 2026
Track software like this
Free during beta