CVE-2026-57120

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.5
MEDIUM

Description

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr. This exposes class, qualified-name, base-class, globals, and object-dictionary attributes to prompt-influenced code when approval is automatically granted, producing a high-impact read primitive without establishing a complete in-process execution chain. This issue is fixed in praisonaiagents 1.6.59.

Published
September 14, 2026 3:17 PM
Last Modified
September 14, 2026 3:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-693

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.