CVE-2026-39888·Python vulnerability
PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted __builtins__ dict and an AST-based blocklist. The AST blocklist embedded inside the subprocess wrapper (blocked_attrs of python_tools.py) contains only 11 attribute names — a strict subset of the 30+ names blocked in the direct-execution path. The four attributes that form a frame-traversal chain out of the sandbox are all absent from the subprocess list (__traceback__, tb_frame, f_back, and f_builtins). Chaining these attributes through a caught exception exposes the real Python builtins dict of the subprocess wrapper frame, from which exec can be retrieved and called under a non-blocked variable name — bypassing every remaining security layer. This vulnerability is fixed in 1.5.115.
- Severity
- critical
- Software
- Python
- Fixed in
- 1.5.115
- Published
- 2026-04-08
Affected versions
Until: 1.5.115
Fixed in: 1.5.115
How to fix this CVE
Update PraisonAI to version 1.5.115 or later to patch the sandbox escape vulnerability in the execute_code() function. This vulnerability allows attackers with limited privileges to bypass sandbox restrictions by chaining frame attributes to access unrestricted Python builtins. Immediately upgrade affected systems and review any code that directly executes user-supplied scripts through PraisonAI agents.
sudo dnf update python3-praisonaiDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check the installed PraisonAI version with: python3 -m pip show praisonai | grep Version
- Step 2: Verify if execute_code() is used in your codebase by searching for 'execute_code' and 'sandbox_mode' in Python files
- Step 3: Review application logs for exception stack traces containing __traceback__, tb_frame, f_back, or f_builtins attributes, which indicate exploitation attempts
- Step 4: After patching, confirm the update with: python3 -m pip show praisonai | grep Version and verify it is 1.5.115 or later
FAQ
What is CVE-2026-39888?
CVE-2026-39888 is a critical sandbox escape vulnerability in PraisonAI's code execution sandbox that allows authenticated users to bypass security restrictions by leveraging frame attribute chains to access unrestricted Python builtins and execute arbitrary code.
Is CVE-2026-39888 being actively exploited?
No, CVE-2026-39888 is not currently listed on the CISA Known Exploited Vulnerabilities catalog, and no public exploit code is available.
What versions of PraisonAI are affected by CVE-2026-39888?
All versions of PraisonAI prior to 1.5.115 are affected by this vulnerability.
How do I check if my server is vulnerable to CVE-2026-39888?
Run 'python3 -m pip show praisonai' and check the Version field. If it is below 1.5.115, your installation is vulnerable.
Does Defensia detect CVE-2026-39888?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PraisonAI is installed on a monitored server, CVE-2026-39888 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-39888. Free for 1 server.
Get started free