CVE-2026-57135High· 7.6▾ MidnightPoC availablePraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Exploit / PoC code exists
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly isolated commands to reach localhost, internal services, cloud metadata, or external hosts and potentially exfiltrate data. An initial remediation was released in version 1.7.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57136High· 8.8PraisonAI is a multi-agent teams system
CVE-2026-57138Critical· 9.9PraisonAI is a multi-agent teams system
CVE-2026-57134High· 8.2PraisonAI is a multi-agent teams system
CVE-2026-57139Critical· 9.8PraisonAI is a multi-agent teams system
GHSA-gqmf-56h7-rrpfHigh· 7.6npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
CVE-2026-57141Critical· 9.8PraisonAI is a multi-agent teams system