CVE-2026-57135: PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

Published Sep 15, 2026
·
Updated

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid httpproxy and httpsproxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly isolated commands to reach localhost, internal services, cloud metadata, or external hosts and potentially exfiltrate data. An initial remediation was released in version 1.7.2.

Affected Software

1 affected component
PraisonAI SandboxExecutor>1.2.3<=1.7.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PraisonAI SandboxExecutor to a version that resolves this vulnerability.

    Fixed in 1.7.2
  2. Compensating control

    Ensure network-isolated mode provides a true operating-system network boundary (not only buildEnv() injection of invalid http_proxy/https_proxy). If OS-level isolation is not available, add an external control such as host/network firewall rules or container/network policy that blocks direct socket egress (including to localhost, internal services, and cloud metadata) from SandboxExecutor-managed processes.

Event History

Sep 15, 2026
CVE Published
via MITRE·10:23 AM
Data Sourced
via MITRE·10:23 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using PraisonAI SandboxExecutor's network-isolated mode are affected from version 1.2.3 through 1.7.2. The mode does not create an operating-system network boundary.

2

What does an attacker need to exploit this?

An attacker needs the ability to cause a command or program to run in the supposedly network-isolated sandbox. The program must use a network client that ignores the injected invalid http_proxy and https_proxy variables and opens sockets directly.

3

What resources could a sandboxed program reach?

A bypassing program may be able to reach localhost services, internal network services, cloud metadata endpoints, or external hosts. This could enable data exfiltration from the environment where the sandbox runs.

4

Is upgrading to version 1.7.2 sufficient?

Version 1.7.2 is identified as the initial remediation release, but the affected range also includes 1.7.2. Review the vendor remediation and use a version confirmed to contain the complete fix.

5

What can be done before a complete fix is deployed?

Do not rely on SandboxExecutor network-isolated mode as a network-security boundary. Run untrusted sandbox commands only in an environment with externally enforced network controls, such as operating-system, container, or network-level egress restrictions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203