Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-57141: PraisonAI codeMode tool lets attackers run system commands

CVE-2026-57141 · published 13 days ago
Summary

Versions of PraisonAI before 1.7.2 let a user who can influence the codeMode tool run their own JavaScript, which can break out of the sandbox and access the server. This could let an attacker read or change files, steal credentials, and execute operating‑system commands using the same rights as the PraisionAI service. Update PraisionAI to version 1.7.2 or later to close the problem.

What to do
  • Update mervinpraison praisonai to version 1.7.2.
Affected software
Ecosystem VendorProductAffected versions
npm mervinpraison praisonai <= 1.7.1
Fix: upgrade to 1.7.2
Original advisory text
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklist can be bypassed with Function('return this')() to recover the global object and by constructing the child_process module name dynamically. An attacker who can influence the code argument can access host process capabilities, read or write files, obtain environment credentials, and execute operating-system commands with the PraisonAI process privileges. This issue is fixed in version 1.7.2.
Severity
9.8 Critical
CVSS 3.1: 9.8 (GHSA)
Type
CWE-94Code Injection
Timeline
Published15 Sep 2026
Updated16 Sep 2026
First seen18 Jun 2026
Sources
Track software like this
Free during beta