CVE-2026-39888
A security flaw in the PraisonAI multi-agent system allows users to break out of the intended code execution sandbox. By using specific Python attributes, an attacker can bypass security restrictions and access the underlying system's core functions.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of the PraisonAI multi-agent teams system prior to version 1.5.115.
Real-world impact
An attacker could execute unauthorized code on the host system, potentially gaining full control over the environment by bypassing the software's built-in security layers.
Why this severity
This vulnerability is rated critical because it allows a low-privileged user to bypass security sandboxing to achieve complete system compromise (high impact on confidentiality, integrity, and availability) via a network-accessible path.
What to do about it
- 01Upgrade PraisonAI to version 1.5.115 or later.
NVD-referenced vendor advisory
Timeline
- Apr 8, 2026 · Apr 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/MervinPraison/PraisonAI/sec…vendor advisory