External risk intelligence

PraisonAI codeMode Untrusted JavaScript Execution Leading to Host Access

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-57138

PraisonAI is a framework for multi-agent systems, often used in development or backend integration environments. While it can be deployed as part of an internet-facing application or API, it is frequently used as an internal library, developer tool, or background service, making public internet exposure plausible but not a standard or required deployment pattern for the product itself.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in PraisonAI, a system for multi-agent teams, that could allow attackers to bypass security controls. The flaw enables unauthorized access to sensitive information, modification of files, command execution, and disruption of the host process by manipulating code execution within the system. This necessitates a review of its integration and potential impact on your environments.

  • A security flaw in PraisonAI allows code to escape its sandbox.
  • It impacts systems that execute untrusted code, potentially exposing data.
  • Confirm PraisonAI relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by controlling input to the `codeMode` feature within the PraisonAI system. This feature, intended to execute JavaScript within a sandbox, incorrectly uses `new Function()`, allowing an attacker to break out of the intended sandbox. By doing so, they can access sensitive information, alter files, and execute commands on the host system.

  • Requires authenticated access with codeMode input control.
  • Triggered by crafting malicious JavaScript input.
  • Risk of data theft, modification, and remote execution.

Live Threat

Current exploitation, exposure, and threat context

When PraisonAI executes untrusted JavaScript code, sensitive information and system operations could be compromised. This occurs when the `codeMode` feature is used, allowing attackers to bypass sandbox restrictions and access critical host system functionalities.

  • System secrets and files at risk.
  • Untrusted code input can gain access.
  • Compromise of host system operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

The PraisonAI multi-agent system's codeMode feature, which executes untrusted JavaScript, is vulnerable to code injection due to insufficient sandboxing. This could allow attackers to read secrets, modify files, or execute commands on the host system. Owners of systems using PraisonAI should first identify all deployments, confirm their reachability and criticality, and then coordinate remediation with the platform or development teams responsible for the PraisonAI integration.

  • Platform/Dev team owns the issue.
  • Verify PraisonAI deployment reachability.
  • Plan coordinated remediation by owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI?

PraisonAI is a framework designed to manage multi-agent teams, which are groups of autonomous AI agents collaborating to solve complex tasks. Developers use it to build automated workflows that can process information or generate outputs. It functions as a library or backend service that coordinates these agents to interact with data and perform operations, often within environments where automated code execution or task handling is required.

Why is CVE-2026-57138 considered a sandbox escape?

The vulnerability stems from improper neutralization of input during dangerous code execution, classified as CWE-184 and CWE-693. While PraisonAI attempts to restrict code using a blocklist and a custom sandbox, it relies on insecure methods to execute JavaScript. An attacker can use specific language features to bypass these restrictions, effectively 'escaping' the sandbox to access the underlying host system's file and process APIs as if they were running local code.

How can an attacker trigger this vulnerability?

The vulnerability is triggered by providing malicious input to the codeMode feature. The system is not triggered by passive interaction; it specifically requires the attacker to have control over the data processed by the codeMode tool. If the input is sanitized or if the feature is not configured to accept user-provided JavaScript, the condition cannot be met.

Do I need to worry if my PraisonAI instance is internal?

According to Halo Surface Signal, PraisonAI is often used as an internal library or backend service, meaning it is not always internet-facing. However, you should still evaluate the risk based on who can supply input to the codeMode feature. If an internal user or another automated service can influence that input, the system remains at risk regardless of its exposure to the public internet.

What should I do if I am running PraisonAI?

First, perform an audit to identify all deployments of PraisonAI within your infrastructure. Once located, coordinate with the development or platform teams responsible for those integrations to verify the version in use. If you are running any version from 1.4.0 up to, but not including, 1.7.2, update to version 1.7.2 or later, which addresses the sandboxing flaws.

References