CVE-2026-34938·Python vulnerability
PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitrary OS command execution on the host. This issue has been patched in version 1.5.90.
- Severity
- critical
- Software
- Python
- Fixed in
- 1.5.90
- Published
- 2026-04-03
Affected versions
Until: 1.5.90
Fixed in: 1.5.90
How to fix this CVE
Update PraisonAI to version 1.5.90 or later to patch a critical sandbox escape vulnerability in the execute_code() function. Organizations using PraisonAI agents should prioritize this update immediately, as the vulnerability allows attackers to bypass multi-layer sandbox protections and execute arbitrary operating system commands. Verify the patched version is deployed across all systems running PraisonAI before resuming agent-based code execution workloads.
sudo dnf update python3-praisonai || pip3 install --upgrade praisonai-agents>=1.5.90Defensia detects this vulnerability
How to check if you are affected
- Check installed PraisonAI version: pip3 show praisonai-agents | grep Version
- Verify execute_code() function is in use: grep -r 'execute_code\|praisonai' /path/to/application --include='*.py' | head -20
- Search application logs for suspicious str subclass instantiations or startswith() method overrides: grep -i 'startswith\|subclass' /var/log/application.log | grep -v '^#'
- Confirm patch installation: pip3 show praisonai-agents | grep Version && python3 -c 'import praisonai_agents; print(praisonai_agents.__version__)' | grep -E '^1\.5\.(9[0-9]|[1-9][0-9]{2,})|^[2-9]'
FAQ
What is CVE-2026-34938?
CVE-2026-34938 is a critical sandbox escape vulnerability in PraisonAI's execute_code() function that allows attackers to bypass security protections by passing a malicious string subclass with an overridden startswith() method, leading to arbitrary OS command execution on the host system.
Is CVE-2026-34938 being actively exploited?
No, CVE-2026-34938 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, the critical CVSS 10.0 severity and ease of exploitation warrant immediate patching.
What versions of PraisonAI are affected by CVE-2026-34938?
All versions of PraisonAI prior to 1.5.90 are vulnerable. The praisonai-agents package versions before 1.5.90 contain the vulnerable execute_code() function.
How do I check if my server is vulnerable to CVE-2026-34938?
Run: pip3 show praisonai-agents | grep Version. If the version is below 1.5.90, your system is vulnerable. Additionally, check if PraisonAI is actively running code execution workloads: ps aux | grep -i praison
Does Defensia detect CVE-2026-34938?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PraisonAI is installed on a monitored server, CVE-2026-34938 will appear in your dashboard with remediation steps and severity alerts.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-34938. Free for 1 server.
Get started free