Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in PraisonAI, a system for multi-agent teams, that could allow attackers to bypass security controls. The flaw enables unauthorized access to sensitive information, modification of files, command execution, and disruption of the host process by manipulating code execution within the system. This necessitates a review of its integration and potential impact on your environments.
- A security flaw in PraisonAI allows code to escape its sandbox.
- It impacts systems that execute untrusted code, potentially exposing data.
- Confirm PraisonAI relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by controlling input to the `codeMode` feature within the PraisonAI system. This feature, intended to execute JavaScript within a sandbox, incorrectly uses `new Function()`, allowing an attacker to break out of the intended sandbox. By doing so, they can access sensitive information, alter files, and execute commands on the host system.
- Requires authenticated access with codeMode input control.
- Triggered by crafting malicious JavaScript input.
- Risk of data theft, modification, and remote execution.
Live Threat
Current exploitation, exposure, and threat context
When PraisonAI executes untrusted JavaScript code, sensitive information and system operations could be compromised. This occurs when the `codeMode` feature is used, allowing attackers to bypass sandbox restrictions and access critical host system functionalities.
- System secrets and files at risk.
- Untrusted code input can gain access.
- Compromise of host system operations.
Operational Fix
Recommended remediation, mitigation, and detection steps
The PraisonAI multi-agent system's codeMode feature, which executes untrusted JavaScript, is vulnerable to code injection due to insufficient sandboxing. This could allow attackers to read secrets, modify files, or execute commands on the host system. Owners of systems using PraisonAI should first identify all deployments, confirm their reachability and criticality, and then coordinate remediation with the platform or development teams responsible for the PraisonAI integration.
- Platform/Dev team owns the issue.
- Verify PraisonAI deployment reachability.
- Plan coordinated remediation by owners.